2020-06-17T10:05:46Z DEBUG Logging to /var/log/ipaserver-install.log 2020-06-17T10:05:46Z DEBUG ipa-server-install was invoked with arguments [] and options: {'unattended': True, 'ip_addresses': [CheckedIPAddress('10.0.0.179')], 'domain_name': 'lin.test.lan', 'realm_name': 'LIN.TEST.LAN', 'host_name': None, 'ca_cert_files': None, 'domain_level': None, 'setup_adtrust': False, 'setup_kra': False, 'setup_dns': True, 'idstart': None, 'idmax': None, 'no_hbac_allow': False, 'no_pkinit': False, 'no_ui_redirect': False, 'dirsrv_config_file': None, 'dirsrv_cert_files': None, 'http_cert_files': None, 'pkinit_cert_files': None, 'dirsrv_cert_name': None, 'http_cert_name': None, 'pkinit_cert_name': None, 'mkhomedir': True, 'ntp_servers': None, 'ntp_pool': None, 'no_ntp': False, 'force_ntpd': False, 'ssh_trust_dns': False, 'no_ssh': False, 'no_sshd': False, 'no_dns_sshfp': False, 'external_ca': False, 'external_ca_type': None, 'external_ca_profile': None, 'external_cert_files': None, 'subject_base': None, 'ca_subject': None, 'ca_signing_algorithm': None, 'pki_config_override': None, 'allow_zone_overlap': False, 'reverse_zones': None, 'no_reverse': True, 'auto_reverse': False, 'zonemgr': None, 'forwarders': [CheckedIPAddressLoopback('10.0.0.1')], 'no_forwarders': False, 'auto_forwarders': False, 'forward_policy': None, 'no_dnssec_validation': False, 'no_host_dns': False, 'enable_compat': False, 'netbios_name': None, 'no_msdcs': False, 'rid_base': None, 'secondary_rid_base': None, 'ignore_topology_disconnect': False, 'ignore_last_of_role': False, 'verbose': False, 'quiet': False, 'log_file': None, 'uninstall': False} 2020-06-17T10:05:46Z DEBUG IPA version 4.8.4-7.module_el8.2.0+374+0d2d74a1 2020-06-17T10:05:46Z DEBUG Searching for an interface of IP address: ::1 2020-06-17T10:05:46Z DEBUG Testing local IP address: ::1/128 (interface: lo) 2020-06-17T10:05:46Z DEBUG Starting external process 2020-06-17T10:05:46Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T10:05:46Z DEBUG Process finished, return code=0 2020-06-17T10:05:46Z DEBUG stdout= 2020-06-17T10:05:46Z DEBUG stderr= 2020-06-17T10:05:46Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:05:46Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:05:46Z DEBUG httpd is not configured 2020-06-17T10:05:46Z DEBUG kadmin is not configured 2020-06-17T10:05:46Z DEBUG dirsrv is not configured 2020-06-17T10:05:46Z DEBUG pki-tomcatd is not configured 2020-06-17T10:05:46Z DEBUG install is not configured 2020-06-17T10:05:46Z DEBUG krb5kdc is not configured 2020-06-17T10:05:46Z DEBUG named is not configured 2020-06-17T10:05:46Z DEBUG filestore is tracking no files 2020-06-17T10:05:46Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2020-06-17T10:05:46Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:05:46Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:05:46Z DEBUG Starting external process 2020-06-17T10:05:46Z DEBUG args=['/bin/systemctl', 'is-enabled', 'ntpd.service'] 2020-06-17T10:05:46Z DEBUG Process finished, return code=1 2020-06-17T10:05:46Z DEBUG stdout= 2020-06-17T10:05:46Z DEBUG stderr=Failed to get unit file state for ntpd.service: No such file or directory 2020-06-17T10:05:46Z DEBUG Starting external process 2020-06-17T10:05:46Z DEBUG args=['/bin/systemctl', 'is-active', 'ntpd.service'] 2020-06-17T10:05:46Z DEBUG Process finished, return code=3 2020-06-17T10:05:46Z DEBUG stdout=inactive 2020-06-17T10:05:46Z DEBUG stderr= 2020-06-17T10:05:46Z DEBUG Check if freeipaserver.lin.test.lan is a primary hostname for localhost 2020-06-17T10:05:46Z DEBUG Primary hostname for localhost: freeipaserver.lin.test.lan 2020-06-17T10:05:46Z DEBUG will use host_name: freeipaserver.lin.test.lan 2020-06-17T10:05:46Z DEBUG Writing configuration file /etc/ipa/default.conf 2020-06-17T10:05:46Z DEBUG [global] host = freeipaserver.lin.test.lan basedn = dc=lin,dc=test,dc=lan realm = LIN.TEST.LAN domain = lin.test.lan xmlrpc_uri = https://freeipaserver.lin.test.lan/ipa/xml ldap_uri = ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket mode = production enable_ra = True ra_plugin = dogtag dogtag_version = 10 2020-06-17T10:05:46Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.aci 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.automember 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.automount 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-06-17T10:05:46Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.batch 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.ca 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.cert 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.config 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.dns 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.group 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-06-17T10:05:46Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.host 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.internal 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.join 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.location 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.migration 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.misc 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.otp 2020-06-17T10:05:46Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.permission 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.ping 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-06-17T10:05:46Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-06-17T10:05:46Z DEBUG importing plugin module ipaserver.plugins.role 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.plugins.schema 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.plugins.server 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.plugins.service 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.plugins.session 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-06-17T10:05:47Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.plugins.topology 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.plugins.trust 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.plugins.user 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.plugins.vault 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-06-17T10:05:47Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-06-17T10:05:47Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.install.plugins.dns 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2020-06-17T10:05:47Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2020-06-17T10:05:48Z DEBUG check_port_bindable: Checking IPv4/IPv6 dual stack and TCP 2020-06-17T10:05:48Z DEBUG check_port_bindable: bind success: 8443/TCP 2020-06-17T10:05:48Z DEBUG check_port_bindable: Checking IPv4/IPv6 dual stack and TCP 2020-06-17T10:05:48Z DEBUG check_port_bindable: bind success: 8080/TCP 2020-06-17T10:05:48Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:05:48Z INFO Checking DNS domain lin.test.lan., please wait ... 2020-06-17T10:05:48Z DEBUG Name freeipaserver.lin.test.lan resolved to {UnsafeIPAddress('10.0.0.179')} 2020-06-17T10:05:48Z DEBUG Searching for an interface of IP address: 10.0.0.179 2020-06-17T10:05:48Z DEBUG Testing local IP address: 127.0.0.1/255.0.0.0 (interface: lo) 2020-06-17T10:05:48Z DEBUG Testing local IP address: 10.0.0.179/255.255.255.0 (interface: enp1s0) 2020-06-17T10:05:48Z DEBUG IP address 10.0.0.179 belongs to a private range, using forward policy only 2020-06-17T10:05:48Z DEBUG Checking DNS server: 10.0.0.1 2020-06-17T10:05:48Z WARNING DNS server 10.0.0.1 does not support DNSSEC: la réponse à la requête « . SOA » ne comporte pas de signatures DNSSEC (pas de données RRSIG) 2020-06-17T10:05:48Z WARNING Please fix forwarder configuration to enable DNSSEC support. (For BIND 9 add directive "dnssec-enable yes;" to "options {}") 2020-06-17T10:05:48Z DEBUG will use DNS forwarders: [CheckedIPAddressLoopback('10.0.0.1')] 2020-06-17T10:05:48Z DEBUG Backing up system configuration file '/etc/hosts' 2020-06-17T10:05:48Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:05:48Z DEBUG Starting external process 2020-06-17T10:05:48Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T10:05:48Z DEBUG Process finished, return code=0 2020-06-17T10:05:48Z DEBUG stdout= 2020-06-17T10:05:48Z DEBUG stderr= 2020-06-17T10:05:48Z DEBUG Starting external process 2020-06-17T10:05:48Z DEBUG args=['/sbin/restorecon', '/etc/pkcs11/modules/softhsm2.module'] 2020-06-17T10:05:48Z DEBUG Process finished, return code=0 2020-06-17T10:05:48Z DEBUG stdout= 2020-06-17T10:05:48Z DEBUG stderr= 2020-06-17T10:05:48Z DEBUG Created PKCS#11 module config '/etc/pkcs11/modules/softhsm2.module'. 2020-06-17T10:05:48Z DEBUG Starting external process 2020-06-17T10:05:48Z DEBUG args=['/bin/systemctl', 'is-enabled', 'ntpd.service'] 2020-06-17T10:05:48Z DEBUG Process finished, return code=1 2020-06-17T10:05:48Z DEBUG stdout= 2020-06-17T10:05:48Z DEBUG stderr=Failed to get unit file state for ntpd.service: No such file or directory 2020-06-17T10:05:48Z DEBUG Starting external process 2020-06-17T10:05:48Z DEBUG args=['/bin/systemctl', 'is-active', 'ntpd.service'] 2020-06-17T10:05:48Z DEBUG Process finished, return code=3 2020-06-17T10:05:48Z DEBUG stdout=inactive 2020-06-17T10:05:48Z DEBUG stderr= 2020-06-17T10:05:48Z DEBUG Search DNS for SRV record of _ntp._udp.None 2020-06-17T10:05:48Z DEBUG DNS record not found: NXDOMAIN 2020-06-17T10:05:48Z INFO Synchronizing time 2020-06-17T10:05:48Z WARNING No SRV records of NTP servers found and no NTP server or pool address was provided. 2020-06-17T10:05:48Z DEBUG Starting external process 2020-06-17T10:05:48Z DEBUG args=['/bin/systemctl', 'enable', 'chronyd.service'] 2020-06-17T10:05:48Z DEBUG Process finished, return code=0 2020-06-17T10:05:48Z DEBUG stdout= 2020-06-17T10:05:48Z DEBUG stderr= 2020-06-17T10:05:48Z DEBUG Starting external process 2020-06-17T10:05:48Z DEBUG args=['/bin/systemctl', 'restart', 'chronyd.service'] 2020-06-17T10:05:48Z DEBUG Process finished, return code=0 2020-06-17T10:05:48Z DEBUG stdout= 2020-06-17T10:05:48Z DEBUG stderr= 2020-06-17T10:05:48Z DEBUG Starting external process 2020-06-17T10:05:48Z DEBUG args=['/bin/systemctl', 'is-active', 'chronyd.service'] 2020-06-17T10:05:48Z DEBUG Process finished, return code=0 2020-06-17T10:05:48Z DEBUG stdout=active 2020-06-17T10:05:48Z DEBUG stderr= 2020-06-17T10:05:48Z DEBUG Restart of chronyd.service complete 2020-06-17T10:05:48Z INFO Attempting to sync time with chronyc. 2020-06-17T10:05:48Z DEBUG Starting external process 2020-06-17T10:05:48Z DEBUG args=['/usr/bin/chronyc', 'waitsync', '3', '-d'] 2020-06-17T10:05:59Z DEBUG Process finished, return code=0 2020-06-17T10:05:59Z DEBUG stdout=try: 1, refid: 00000000, correction: 0.000000000, skew: 0.000 try: 2, refid: 05C4C03A, correction: 0.000220896, skew: 6.622 2020-06-17T10:05:59Z DEBUG stderr= 2020-06-17T10:05:59Z INFO Time synchronization was successful. 2020-06-17T10:05:59Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:05:59Z DEBUG Configuring directory server (dirsrv). Estimated time: 30 seconds 2020-06-17T10:05:59Z DEBUG [1/44]: creating directory server instance 2020-06-17T10:05:59Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:05:59Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:05:59Z DEBUG Running setup with verbose 2020-06-17T10:05:59Z DEBUG START: Starting installation... 2020-06-17T10:05:59Z DEBUG READY: Preparing installation for LIN-TEST-LAN... 2020-06-17T10:05:59Z DEBUG PASSED: using config settings 999999999 2020-06-17T10:05:59Z DEBUG PASSED: user / group checking 2020-06-17T10:05:59Z DEBUG PASSED: prefix checking 2020-06-17T10:05:59Z DEBUG list instance not found in /etc/dirsrv/slapd-LIN-TEST-LAN/dse.ldif: LIN-TEST-LAN 2020-06-17T10:05:59Z DEBUG PASSED: instance checking 2020-06-17T10:05:59Z DEBUG INFO: temp root password set to QvRQYOEjYc51pws0ijOy4.Oqj1EQwCzvul1OvTs8qhTSQlB6yMx3RnrIJBam7eClR 2020-06-17T10:05:59Z DEBUG PASSED: root user checking 2020-06-17T10:05:59Z DEBUG PASSED: network avaliability checking 2020-06-17T10:05:59Z DEBUG READY: Beginning installation for LIN-TEST-LAN... 2020-06-17T10:05:59Z DEBUG ACTION: Creating dse.ldif 2020-06-17T10:05:59Z DEBUG ACTION: creating /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:05:59Z DEBUG ACTION: creating /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:05:59Z DEBUG ACTION: creating /var/lib/dirsrv/slapd-LIN-TEST-LAN/db 2020-06-17T10:05:59Z DEBUG ACTION: creating /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:05:59Z DEBUG ACTION: creating /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:05:59Z DEBUG ACTION: creating /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:05:59Z DEBUG ACTION: creating /var/run/dirsrv 2020-06-17T10:05:59Z DEBUG CMD: systemctl enable dirsrv@LIN-TEST-LAN ; STDOUT: b'' ; STDERR: b'Created symlink /etc/systemd/system/multi-user.target.wants/dirsrv@LIN-TEST-LAN.service \xe2\x86\x92 /usr/lib/systemd/system/dirsrv@.service.\n' 2020-06-17T10:05:59Z DEBUG ACTION: Creating certificate database is /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:05:59Z DEBUG Allocate with None 2020-06-17T10:05:59Z DEBUG Allocate with freeipaserver.lin.test.lan:389 2020-06-17T10:05:59Z DEBUG Allocate with freeipaserver.lin.test.lan:389 2020-06-17T10:05:59Z DEBUG nss cmd: /usr/bin/certutil -N -d /etc/dirsrv/slapd-LIN-TEST-LAN -f /etc/dirsrv/slapd-LIN-TEST-LAN/pwdfile.txt 2020-06-17T10:05:59Z DEBUG nss output: 2020-06-17T10:05:59Z DEBUG nss cmd: /usr/bin/certutil -N -d /etc/dirsrv/ssca/ -f /etc/dirsrv/ssca//pwdfile.txt 2020-06-17T10:05:59Z DEBUG nss output: 2020-06-17T10:06:00Z DEBUG nss cmd: /usr/bin/certutil -S -n Self-Signed-CA -s CN=ssca.389ds.example.com,O=testing,L=389ds,ST=Queensland,C=AU -x -g 4096 -t CT,, -v 24 --keyUsage certSigning -d /etc/dirsrv/ssca/ -z /etc/dirsrv/ssca//noise.txt -f /etc/dirsrv/ssca//pwdfile.txt 2020-06-17T10:06:01Z DEBUG nss output: Generating key. This may take a few moments... 2020-06-17T10:06:01Z DEBUG nss cmd: /usr/bin/certutil -L -n Self-Signed-CA -d /etc/dirsrv/ssca/ -a 2020-06-17T10:06:01Z DEBUG nss cmd: /usr/bin/c_rehash /etc/dirsrv/ssca/ 2020-06-17T10:06:01Z DEBUG CSR subject -> CN=freeipaserver.lin.test.lan,givenName=e662263f-1d9c-42c9-877c-674d5821fb81,O=testing,L=389ds,ST=Queensland,C=AU 2020-06-17T10:06:01Z DEBUG CSR alt_names -> ['freeipaserver.lin.test.lan'] 2020-06-17T10:06:02Z DEBUG nss cmd: /usr/bin/certutil -R --keyUsage digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment --nsCertType sslClient,sslServer --extKeyUsage clientAuth,serverAuth -s CN=freeipaserver.lin.test.lan,givenName=e662263f-1d9c-42c9-877c-674d5821fb81,O=testing,L=389ds,ST=Queensland,C=AU -8 freeipaserver.lin.test.lan -g 4096 -d /etc/dirsrv/slapd-LIN-TEST-LAN -z /etc/dirsrv/slapd-LIN-TEST-LAN/noise.txt -f /etc/dirsrv/slapd-LIN-TEST-LAN/pwdfile.txt -a -o /etc/dirsrv/slapd-LIN-TEST-LAN/Server-Cert.csr 2020-06-17T10:06:04Z DEBUG nss cmd: /usr/bin/certutil -C -d /etc/dirsrv/ssca/ -f /etc/dirsrv/ssca//pwdfile.txt -v 24 -a -i /etc/dirsrv/slapd-LIN-TEST-LAN/Server-Cert.csr -o /etc/dirsrv/slapd-LIN-TEST-LAN/Server-Cert.crt -c Self-Signed-CA 2020-06-17T10:06:04Z DEBUG nss cmd: /usr/bin/c_rehash /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:06:04Z DEBUG nss cmd: /usr/bin/certutil -A -n Self-Signed-CA -t CT,, -a -i /etc/dirsrv/slapd-LIN-TEST-LAN/ca.crt -d /etc/dirsrv/slapd-LIN-TEST-LAN -f /etc/dirsrv/slapd-LIN-TEST-LAN/pwdfile.txt 2020-06-17T10:06:04Z DEBUG nss cmd: /usr/bin/certutil -A -n Server-Cert -t ,, -a -i /etc/dirsrv/slapd-LIN-TEST-LAN/Server-Cert.crt -d /etc/dirsrv/slapd-LIN-TEST-LAN -f /etc/dirsrv/slapd-LIN-TEST-LAN/pwdfile.txt 2020-06-17T10:06:04Z DEBUG nss cmd: /usr/bin/certutil -V -d /etc/dirsrv/slapd-LIN-TEST-LAN -n Server-Cert -u YCV 2020-06-17T10:06:04Z DEBUG port 636 already in [389, 636, 3268, 3269, 7389], skipping port relabel 2020-06-17T10:06:04Z DEBUG port 389 already in [389, 636, 3268, 3269, 7389], skipping port relabel 2020-06-17T10:06:04Z DEBUG systemd status -> True 2020-06-17T10:06:04Z DEBUG systemd status -> True 2020-06-17T10:06:05Z DEBUG open(): Connecting to uri ldap://freeipaserver.lin.test.lan:389/ 2020-06-17T10:06:05Z DEBUG Using dirsrv ca certificate /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:06:05Z DEBUG Using external ca certificate /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:06:05Z DEBUG Using external ca certificate /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:06:05Z DEBUG Using certificate policy 1 2020-06-17T10:06:05Z DEBUG ldap.OPT_X_TLS_REQUIRE_CERT = 1 2020-06-17T10:06:05Z DEBUG open(): bound as cn=Directory Manager 2020-06-17T10:06:05Z DEBUG open(): Connecting to uri ldap://freeipaserver.lin.test.lan:389/ 2020-06-17T10:06:05Z DEBUG Using dirsrv ca certificate /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:06:05Z DEBUG Using external ca certificate /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:06:05Z DEBUG Using external ca certificate /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:06:05Z DEBUG Using certificate policy 1 2020-06-17T10:06:05Z DEBUG ldap.OPT_X_TLS_REQUIRE_CERT = 1 2020-06-17T10:06:06Z DEBUG open(): bound as cn=Directory Manager 2020-06-17T10:06:06Z DEBUG cn=config set REPLACE: ('nsslapd-secureport', '636') 2020-06-17T10:06:06Z DEBUG cn=config set REPLACE: ('nsslapd-security', 'on') 2020-06-17T10:06:06Z DEBUG Checking "None" under cn=ldbm database,cn=plugins,cn=config : {'cn': 'userRoot', 'nsslapd-suffix': 'dc=lin,dc=test,dc=lan'} 2020-06-17T10:06:06Z DEBUG Using first property cn: userRoot as rdn 2020-06-17T10:06:06Z DEBUG _gen_selector filter = (&(&(objectclass=nsMappingTree))(|(cn=dc=lin,dc=test,dc=lan)(nsslapd-backend=dc=lin,dc=test,dc=lan))) 2020-06-17T10:06:06Z DEBUG _gen_selector filter = (&(&(objectclass=nsMappingTree))(|(cn=userRoot)(nsslapd-backend=userRoot))) 2020-06-17T10:06:06Z DEBUG Validated dn cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:06:06Z DEBUG Creating cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:06:06Z DEBUG updating dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:06:06Z DEBUG updated dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config with {'objectclass': [b'top', b'extensibleObject', b'nsBackendInstance']} 2020-06-17T10:06:06Z DEBUG updating dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:06:06Z DEBUG updated dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config with {'cn': [b'userRoot'], 'nsslapd-suffix': [b'dc=lin,dc=test,dc=lan']} 2020-06-17T10:06:06Z DEBUG Created entry cn=userRoot,cn=ldbm database,cn=plugins,cn=config : {'objectclass': [b'top', b'extensibleObject', b'nsBackendInstance'], 'cn': [b'userRoot'], 'nsslapd-suffix': [b'dc=lin,dc=test,dc=lan']} 2020-06-17T10:06:06Z DEBUG Checking "None" under cn=mapping tree,cn=config : {'cn': [b'dc=lin,dc=test,dc=lan'], 'nsslapd-state': 'backend', 'nsslapd-backend': [b'userRoot']} 2020-06-17T10:06:06Z DEBUG Using first property cn: dc\=lin\,dc\=test\,dc\=lan as rdn 2020-06-17T10:06:06Z DEBUG Validated dn cn=dc\=lin\,dc\=test\,dc\=lan,cn=mapping tree,cn=config 2020-06-17T10:06:06Z DEBUG Creating cn=dc\=lin\,dc\=test\,dc\=lan,cn=mapping tree,cn=config 2020-06-17T10:06:06Z DEBUG updating dn: cn=dc\=lin\,dc\=test\,dc\=lan,cn=mapping tree,cn=config 2020-06-17T10:06:06Z DEBUG updated dn: cn=dc\=lin\,dc\=test\,dc\=lan,cn=mapping tree,cn=config with {'objectclass': [b'top', b'extensibleObject', b'nsMappingTree']} 2020-06-17T10:06:06Z DEBUG updating dn: cn=dc\=lin\,dc\=test\,dc\=lan,cn=mapping tree,cn=config 2020-06-17T10:06:06Z DEBUG updated dn: cn=dc\=lin\,dc\=test\,dc\=lan,cn=mapping tree,cn=config with {'cn': [b'dc=lin,dc=test,dc=lan', b'dc\\=lin\\,dc\\=test\\,dc\\=lan'], 'nsslapd-state': [b'backend'], 'nsslapd-backend': [b'userRoot']} 2020-06-17T10:06:06Z DEBUG Created entry cn=dc\=lin\,dc\=test\,dc\=lan,cn=mapping tree,cn=config : {'objectclass': [b'top', b'extensibleObject', b'nsMappingTree'], 'cn': [b'dc=lin,dc=test,dc=lan', b'dc\\=lin\\,dc\\=test\\,dc\\=lan'], 'nsslapd-state': [b'backend'], 'nsslapd-backend': [b'userRoot']} 2020-06-17T10:06:06Z DEBUG cn=config set REPLACE: ('nsslapd-ldapifilepath', '/var/run/slapd-LIN-TEST-LAN.socket') 2020-06-17T10:06:06Z DEBUG cn=config set REPLACE: ('nsslapd-ldapilisten', 'on') 2020-06-17T10:06:06Z DEBUG cn=config set REPLACE: ('nsslapd-ldapiautobind', 'on') 2020-06-17T10:06:06Z DEBUG cn=config set REPLACE: ('nsslapd-ldapimaprootdn', 'cn=Directory Manager') 2020-06-17T10:06:06Z DEBUG Adding sasl maps for suffix dc=lin,dc=test,dc=lan 2020-06-17T10:06:06Z DEBUG Checking "None" under cn=mapping,cn=sasl,cn=config : {'cn': 'rfc 2829 u syntax', 'nsSaslMapRegexString': '^u:\\(.*\\)', 'nsSaslMapBaseDNTemplate': 'dc=lin,dc=test,dc=lan', 'nsSaslMapFilterTemplate': '(uid=\\1)'} 2020-06-17T10:06:06Z DEBUG Using first property cn: rfc 2829 u syntax as rdn 2020-06-17T10:06:06Z DEBUG Validated dn cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config 2020-06-17T10:06:06Z DEBUG Creating cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config 2020-06-17T10:06:06Z DEBUG updating dn: cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config 2020-06-17T10:06:06Z DEBUG updated dn: cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config with {'objectclass': [b'top', b'nsSaslMapping']} 2020-06-17T10:06:06Z DEBUG updating dn: cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config 2020-06-17T10:06:06Z DEBUG updated dn: cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config with {'cn': [b'rfc 2829 u syntax'], 'nsSaslMapRegexString': [b'^u:\\(.*\\)'], 'nsSaslMapBaseDNTemplate': [b'dc=lin,dc=test,dc=lan'], 'nsSaslMapFilterTemplate': [b'(uid=\\1)']} 2020-06-17T10:06:06Z DEBUG Created entry cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config : {'objectclass': [b'top', b'nsSaslMapping'], 'cn': [b'rfc 2829 u syntax'], 'nsSaslMapRegexString': [b'^u:\\(.*\\)'], 'nsSaslMapBaseDNTemplate': [b'dc=lin,dc=test,dc=lan'], 'nsSaslMapFilterTemplate': [b'(uid=\\1)']} 2020-06-17T10:06:06Z DEBUG Checking "None" under cn=mapping,cn=sasl,cn=config : {'cn': 'uid mapping', 'nsSaslMapRegexString': '^[^:@]+$', 'nsSaslMapBaseDNTemplate': 'dc=lin,dc=test,dc=lan', 'nsSaslMapFilterTemplate': '(uid=&)'} 2020-06-17T10:06:06Z DEBUG Using first property cn: uid mapping as rdn 2020-06-17T10:06:06Z DEBUG Validated dn cn=uid mapping,cn=mapping,cn=sasl,cn=config 2020-06-17T10:06:06Z DEBUG Creating cn=uid mapping,cn=mapping,cn=sasl,cn=config 2020-06-17T10:06:06Z DEBUG updating dn: cn=uid mapping,cn=mapping,cn=sasl,cn=config 2020-06-17T10:06:06Z DEBUG updated dn: cn=uid mapping,cn=mapping,cn=sasl,cn=config with {'objectclass': [b'top', b'nsSaslMapping']} 2020-06-17T10:06:06Z DEBUG updating dn: cn=uid mapping,cn=mapping,cn=sasl,cn=config 2020-06-17T10:06:06Z DEBUG updated dn: cn=uid mapping,cn=mapping,cn=sasl,cn=config with {'cn': [b'uid mapping'], 'nsSaslMapRegexString': [b'^[^:@]+$'], 'nsSaslMapBaseDNTemplate': [b'dc=lin,dc=test,dc=lan'], 'nsSaslMapFilterTemplate': [b'(uid=&)']} 2020-06-17T10:06:06Z DEBUG Created entry cn=uid mapping,cn=mapping,cn=sasl,cn=config : {'objectclass': [b'top', b'nsSaslMapping'], 'cn': [b'uid mapping'], 'nsSaslMapRegexString': [b'^[^:@]+$'], 'nsSaslMapBaseDNTemplate': [b'dc=lin,dc=test,dc=lan'], 'nsSaslMapFilterTemplate': [b'(uid=&)']} 2020-06-17T10:06:06Z DEBUG cn=config set REPLACE: ('nsslapd-rootpw', '********') 2020-06-17T10:06:06Z DEBUG systemd status -> True 2020-06-17T10:06:06Z DEBUG systemd status -> True 2020-06-17T10:06:09Z DEBUG systemd status -> True 2020-06-17T10:06:09Z DEBUG systemd status -> True 2020-06-17T10:06:10Z DEBUG FINISH: Completed installation for LIN-TEST-LAN 2020-06-17T10:06:10Z DEBUG Allocate local instance with ldapi://%2fvar%2frun%2fslapd-LIN-TEST-LAN.socket 2020-06-17T10:06:10Z DEBUG open(): Connecting to uri ldapi://%2fvar%2frun%2fslapd-LIN-TEST-LAN.socket 2020-06-17T10:06:10Z DEBUG Using dirsrv ca certificate /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:06:10Z DEBUG Using external ca certificate /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:06:10Z DEBUG Using external ca certificate /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:06:10Z DEBUG Using certificate policy 1 2020-06-17T10:06:10Z DEBUG ldap.OPT_X_TLS_REQUIRE_CERT = 1 2020-06-17T10:06:10Z DEBUG open(): bound as cn=Directory Manager 2020-06-17T10:06:10Z DEBUG Checking "None" under None : {'dc': 'lin', 'info': 'IPA V2.0'} 2020-06-17T10:06:10Z DEBUG Validated dn dc=lin,dc=test,dc=lan 2020-06-17T10:06:10Z DEBUG Creating dc=lin,dc=test,dc=lan 2020-06-17T10:06:10Z DEBUG updating dn: dc=lin,dc=test,dc=lan 2020-06-17T10:06:10Z DEBUG updated dn: dc=lin,dc=test,dc=lan with {'objectclass': [b'top', b'domain', b'pilotObject']} 2020-06-17T10:06:10Z DEBUG updating dn: dc=lin,dc=test,dc=lan 2020-06-17T10:06:10Z DEBUG updated dn: dc=lin,dc=test,dc=lan with {'dc': [b'lin'], 'info': [b'IPA V2.0']} 2020-06-17T10:06:10Z DEBUG Created entry dc=lin,dc=test,dc=lan : {'objectclass': [b'top', b'domain', b'pilotObject'], 'dc': [b'lin'], 'info': [b'IPA V2.0']} 2020-06-17T10:06:10Z DEBUG completed creating DS instance 2020-06-17T10:06:10Z DEBUG step duration: dirsrv __create_instance 11.81 sec 2020-06-17T10:06:10Z DEBUG [2/44]: configure autobind for root 2020-06-17T10:06:10Z DEBUG Starting external process 2020-06-17T10:06:10Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/root-autobind.ldif', '-H', 'ldapi://%2fvar%2frun%2fslapd-LIN-TEST-LAN.socket', '-x', '-D', 'cn=Directory Manager', '-y', '/tmp/tmpi_w5rho5'] 2020-06-17T10:06:10Z DEBUG Process finished, return code=0 2020-06-17T10:06:10Z DEBUG stdout=add objectClass: extensibleObject top add cn: root-autobind add uidNumber: 0 add gidNumber: 0 adding new entry "cn=root-autobind,cn=config" modify complete replace nsslapd-ldapiautobind: on modifying entry "cn=config" modify complete replace nsslapd-ldapimaptoentries: on modifying entry "cn=config" modify complete 2020-06-17T10:06:10Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) 2020-06-17T10:06:10Z DEBUG step duration: dirsrv __root_autobind 0.06 sec 2020-06-17T10:06:10Z DEBUG [3/44]: stopping directory server 2020-06-17T10:06:10Z DEBUG Starting external process 2020-06-17T10:06:10Z DEBUG args=['/bin/systemctl', 'stop', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:06:13Z DEBUG Process finished, return code=0 2020-06-17T10:06:13Z DEBUG stdout= 2020-06-17T10:06:13Z DEBUG stderr= 2020-06-17T10:06:13Z DEBUG Stop of dirsrv@LIN-TEST-LAN.service complete 2020-06-17T10:06:13Z DEBUG step duration: dirsrv __stop_instance 2.29 sec 2020-06-17T10:06:13Z DEBUG [4/44]: updating configuration in dse.ldif 2020-06-17T10:06:13Z DEBUG Starting external process 2020-06-17T10:06:13Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T10:06:13Z DEBUG Process finished, return code=0 2020-06-17T10:06:13Z DEBUG stdout= 2020-06-17T10:06:13Z DEBUG stderr= 2020-06-17T10:06:13Z DEBUG Starting external process 2020-06-17T10:06:13Z DEBUG args=['/sbin/restorecon', '/etc/dirsrv/slapd-LIN-TEST-LAN/dse.ldif'] 2020-06-17T10:06:13Z DEBUG Process finished, return code=0 2020-06-17T10:06:13Z DEBUG stdout= 2020-06-17T10:06:13Z DEBUG stderr= 2020-06-17T10:06:13Z DEBUG step duration: dirsrv __update_dse_ldif 0.06 sec 2020-06-17T10:06:13Z DEBUG [5/44]: starting directory server 2020-06-17T10:06:13Z DEBUG Starting external process 2020-06-17T10:06:13Z DEBUG args=['/bin/systemctl', 'start', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:06:14Z DEBUG Process finished, return code=0 2020-06-17T10:06:14Z DEBUG stdout= 2020-06-17T10:06:14Z DEBUG stderr= 2020-06-17T10:06:14Z DEBUG Starting external process 2020-06-17T10:06:14Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:06:14Z DEBUG Process finished, return code=0 2020-06-17T10:06:14Z DEBUG stdout=active 2020-06-17T10:06:14Z DEBUG stderr= 2020-06-17T10:06:14Z DEBUG wait_for_open_ports: localhost [389] timeout 120 2020-06-17T10:06:14Z DEBUG waiting for port: 389 2020-06-17T10:06:14Z DEBUG SUCCESS: port: 389 2020-06-17T10:06:14Z DEBUG Start of dirsrv@LIN-TEST-LAN.service complete 2020-06-17T10:06:14Z DEBUG Created connection context.ldap2_139850008098072 2020-06-17T10:06:14Z DEBUG step duration: dirsrv __start_instance 1.40 sec 2020-06-17T10:06:14Z DEBUG [6/44]: adding default schema 2020-06-17T10:06:14Z DEBUG step duration: dirsrv __add_default_schemas 0.00 sec 2020-06-17T10:06:14Z DEBUG [7/44]: enabling memberof plugin 2020-06-17T10:06:14Z DEBUG Starting external process 2020-06-17T10:06:14Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/memberof-conf.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:14Z DEBUG Process finished, return code=0 2020-06-17T10:06:14Z DEBUG stdout=replace nsslapd-pluginenabled: on add memberofgroupattr: memberUser add memberofgroupattr: memberHost modifying entry "cn=MemberOf Plugin,cn=plugins,cn=config" modify complete 2020-06-17T10:06:14Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:14Z DEBUG step duration: dirsrv __add_memberof_module 0.01 sec 2020-06-17T10:06:14Z DEBUG [8/44]: enabling winsync plugin 2020-06-17T10:06:14Z DEBUG Starting external process 2020-06-17T10:06:14Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/ipa-winsync-conf.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:14Z DEBUG Process finished, return code=0 2020-06-17T10:06:14Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa-winsync add nsslapd-pluginpath: libipa_winsync add nsslapd-plugininitfunc: ipa_winsync_plugin_init add nsslapd-pluginDescription: Allows IPA to work with the DS windows sync feature add nsslapd-pluginid: ipa-winsync add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: on add nsslapd-plugin-depends-on-type: database add ipaWinSyncRealmFilter: (objectclass=krbRealmContainer) add ipaWinSyncRealmAttr: cn add ipaWinSyncNewEntryFilter: (cn=ipaConfig) add ipaWinSyncNewUserOCAttr: ipauserobjectclasses add ipaWinSyncUserFlatten: true add ipaWinsyncHomeDirAttr: ipaHomesRootDir add ipaWinsyncLoginShellAttr: ipaDefaultLoginShell add ipaWinSyncDefaultGroupAttr: ipaDefaultPrimaryGroup add ipaWinSyncDefaultGroupFilter: (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) add ipaWinSyncAcctDisable: both add ipaWinSyncForceSync: true add ipaWinSyncUserAttr: uidNumber -1 gidNumber -1 adding new entry "cn=ipa-winsync,cn=plugins,cn=config" modify complete 2020-06-17T10:06:14Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:14Z DEBUG step duration: dirsrv __add_winsync_module 0.02 sec 2020-06-17T10:06:14Z DEBUG [9/44]: configure password logging 2020-06-17T10:06:14Z DEBUG Starting external process 2020-06-17T10:06:14Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/pw-logging-conf.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:14Z DEBUG Process finished, return code=0 2020-06-17T10:06:14Z DEBUG stdout=replace nsslapd-unhashed-pw-switch: nolog modifying entry "cn=config" modify complete 2020-06-17T10:06:14Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:14Z DEBUG step duration: dirsrv __password_logging 0.02 sec 2020-06-17T10:06:14Z DEBUG [10/44]: configuring replication version plugin 2020-06-17T10:06:14Z DEBUG Starting external process 2020-06-17T10:06:14Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/version-conf.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:14Z DEBUG Process finished, return code=0 2020-06-17T10:06:14Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA Version Replication add nsslapd-pluginpath: libipa_repl_version add nsslapd-plugininitfunc: repl_version_plugin_init add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: off add nsslapd-pluginid: ipa_repl_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA Replication version plugin add nsslapd-plugin-depends-on-type: database add nsslapd-plugin-depends-on-named: Multimaster Replication Plugin adding new entry "cn=IPA Version Replication,cn=plugins,cn=config" modify complete 2020-06-17T10:06:14Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:14Z DEBUG step duration: dirsrv __config_version_module 0.01 sec 2020-06-17T10:06:14Z DEBUG [11/44]: enabling IPA enrollment plugin 2020-06-17T10:06:14Z DEBUG Starting external process 2020-06-17T10:06:14Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpo3ufmx92', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:14Z DEBUG Process finished, return code=0 2020-06-17T10:06:14Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa_enrollment_extop add nsslapd-pluginpath: libipa_enrollment_extop add nsslapd-plugininitfunc: ipaenrollment_init add nsslapd-plugintype: extendedop add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_enrollment_extop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: RedHat add nsslapd-plugindescription: Enroll hosts into the IPA domain add nsslapd-plugin-depends-on-type: database add nsslapd-realmTree: dc=lin,dc=test,dc=lan adding new entry "cn=ipa_enrollment_extop,cn=plugins,cn=config" modify complete 2020-06-17T10:06:14Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:14Z DEBUG step duration: dirsrv __add_enrollment_module 0.02 sec 2020-06-17T10:06:14Z DEBUG [12/44]: configuring uniqueness plugin 2020-06-17T10:06:14Z DEBUG Starting external process 2020-06-17T10:06:14Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpll0z_v37', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:14Z DEBUG Process finished, return code=0 2020-06-17T10:06:14Z DEBUG stdout=add objectClass: top nsSlapdPlugin extensibleObject add cn: krbPrincipalName uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: krbPrincipalName add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values add uniqueness-subtrees: dc=lin,dc=test,dc=lan add uniqueness-exclude-subtrees: cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan add uniqueness-across-all-subtrees: on adding new entry "cn=krbPrincipalName uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: krbCanonicalName uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: krbCanonicalName add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values add uniqueness-subtrees: dc=lin,dc=test,dc=lan add uniqueness-exclude-subtrees: cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan add uniqueness-across-all-subtrees: on adding new entry "cn=krbCanonicalName uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: netgroup uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: cn add uniqueness-subtrees: cn=ng,cn=alt,dc=lin,dc=test,dc=lan add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values adding new entry "cn=netgroup uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: ipaUniqueID uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: ipaUniqueID add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values add uniqueness-subtrees: dc=lin,dc=test,dc=lan add uniqueness-exclude-subtrees: cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan add uniqueness-across-all-subtrees: on adding new entry "cn=ipaUniqueID uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: sudorule name uniqueness add nsslapd-pluginDescription: Enforce unique attribute values add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: cn add uniqueness-subtrees: cn=sudorules,cn=sudo,dc=lin,dc=test,dc=lan add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project adding new entry "cn=sudorule name uniqueness,cn=plugins,cn=config" modify complete 2020-06-17T10:06:14Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:14Z DEBUG step duration: dirsrv __set_unique_attrs 0.03 sec 2020-06-17T10:06:14Z DEBUG [13/44]: configuring uuid plugin 2020-06-17T10:06:14Z DEBUG Starting external process 2020-06-17T10:06:14Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/uuid-conf.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:14Z DEBUG Process finished, return code=0 2020-06-17T10:06:14Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA UUID add nsslapd-pluginpath: libipa_uuid add nsslapd-plugininitfunc: ipauuid_init add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipauuid_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA UUID plugin add nsslapd-plugin-depends-on-type: database adding new entry "cn=IPA UUID,cn=plugins,cn=config" modify complete 2020-06-17T10:06:14Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:14Z DEBUG Starting external process 2020-06-17T10:06:14Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpk6pwk79n', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:14Z DEBUG Process finished, return code=0 2020-06-17T10:06:14Z DEBUG stdout=add objectclass: top extensibleObject add cn: IPA Unique IDs add ipaUuidAttr: ipaUniqueID add ipaUuidMagicRegen: autogenerate add ipaUuidFilter: (|(objectclass=ipaObject)(objectclass=ipaAssociation)) add ipaUuidScope: dc=lin,dc=test,dc=lan add ipaUuidEnforce: TRUE adding new entry "cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config" modify complete add objectclass: top extensibleObject add cn: IPK11 Unique IDs add ipaUuidAttr: ipk11UniqueID add ipaUuidMagicRegen: autogenerate add ipaUuidFilter: (objectclass=ipk11Object) add ipaUuidScope: dc=lin,dc=test,dc=lan add ipaUuidEnforce: FALSE adding new entry "cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config" modify complete 2020-06-17T10:06:14Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:14Z DEBUG step duration: dirsrv __config_uuid_module 0.03 sec 2020-06-17T10:06:14Z DEBUG [14/44]: configuring modrdn plugin 2020-06-17T10:06:14Z DEBUG Starting external process 2020-06-17T10:06:14Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/modrdn-conf.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:14Z DEBUG Process finished, return code=0 2020-06-17T10:06:14Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA MODRDN add nsslapd-pluginpath: libipa_modrdn add nsslapd-plugininitfunc: ipamodrdn_init add nsslapd-plugintype: betxnpostoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipamodrdn_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA MODRDN plugin add nsslapd-plugin-depends-on-type: database add nsslapd-pluginPrecedence: 60 adding new entry "cn=IPA MODRDN,cn=plugins,cn=config" modify complete 2020-06-17T10:06:14Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:14Z DEBUG Starting external process 2020-06-17T10:06:14Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpeo9er7s3', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:14Z DEBUG Process finished, return code=0 2020-06-17T10:06:14Z DEBUG stdout=add objectclass: top extensibleObject add cn: Kerberos Principal Name add ipaModRDNsourceAttr: uid add ipaModRDNtargetAttr: krbPrincipalName add ipaModRDNsuffix: @LIN.TEST.LAN add ipaModRDNfilter: (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) add ipaModRDNscope: dc=lin,dc=test,dc=lan adding new entry "cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config" modify complete add objectclass: top extensibleObject add cn: Kerberos Canonical Name add ipaModRDNsourceAttr: uid add ipaModRDNtargetAttr: krbCanonicalName add ipaModRDNsuffix: @LIN.TEST.LAN add ipaModRDNfilter: (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) add ipaModRDNscope: dc=lin,dc=test,dc=lan adding new entry "cn=Kerberos Canonical Name,cn=IPA MODRDN,cn=plugins,cn=config" modify complete 2020-06-17T10:06:14Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:14Z DEBUG step duration: dirsrv __config_modrdn_module 0.03 sec 2020-06-17T10:06:14Z DEBUG [15/44]: configuring DNS plugin 2020-06-17T10:06:14Z DEBUG Starting external process 2020-06-17T10:06:14Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/ipa-dns-conf.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:14Z DEBUG Process finished, return code=0 2020-06-17T10:06:14Z DEBUG stdout=add objectclass: top nsslapdPlugin extensibleObject add cn: IPA DNS add nsslapd-plugindescription: IPA DNS support plugin add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_dns add nsslapd-plugininitfunc: ipadns_init add nsslapd-pluginpath: libipa_dns.so add nsslapd-plugintype: preoperation add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-pluginversion: 1.0 add nsslapd-plugin-depends-on-type: database adding new entry "cn=IPA DNS,cn=plugins,cn=config" modify complete 2020-06-17T10:06:14Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:14Z DEBUG step duration: dirsrv __config_dns_module 0.01 sec 2020-06-17T10:06:14Z DEBUG [16/44]: enabling entryUSN plugin 2020-06-17T10:06:14Z DEBUG Starting external process 2020-06-17T10:06:14Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/entryusn.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:14Z DEBUG Process finished, return code=0 2020-06-17T10:06:14Z DEBUG stdout=replace nsslapd-entryusn-global: on modifying entry "cn=config" modify complete replace nsslapd-entryusn-import-initval: next modifying entry "cn=config" modify complete replace nsslapd-pluginenabled: on modifying entry "cn=USN,cn=plugins,cn=config" modify complete 2020-06-17T10:06:14Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:14Z DEBUG step duration: dirsrv __enable_entryusn 0.03 sec 2020-06-17T10:06:14Z DEBUG [17/44]: configuring lockout plugin 2020-06-17T10:06:14Z DEBUG Starting external process 2020-06-17T10:06:14Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/lockout-conf.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:14Z DEBUG Process finished, return code=0 2020-06-17T10:06:14Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA Lockout add nsslapd-pluginpath: libipa_lockout add nsslapd-plugininitfunc: ipalockout_init add nsslapd-plugintype: object add nsslapd-pluginenabled: on add nsslapd-pluginid: ipalockout_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA Lockout plugin add nsslapd-plugin-depends-on-type: database adding new entry "cn=IPA Lockout,cn=plugins,cn=config" modify complete 2020-06-17T10:06:14Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:14Z DEBUG step duration: dirsrv __config_lockout_module 0.01 sec 2020-06-17T10:06:14Z DEBUG [18/44]: configuring topology plugin 2020-06-17T10:06:14Z DEBUG Starting external process 2020-06-17T10:06:14Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp97_jqwxm', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:14Z DEBUG Process finished, return code=0 2020-06-17T10:06:14Z DEBUG stdout=add objectClass: top nsSlapdPlugin extensibleObject add cn: IPA Topology Configuration add nsslapd-pluginPath: libtopology add nsslapd-pluginInitfunc: ipa_topo_init add nsslapd-pluginType: object add nsslapd-pluginEnabled: on add nsslapd-topo-plugin-shared-config-base: cn=ipa,cn=etc,dc=lin,dc=test,dc=lan add nsslapd-topo-plugin-shared-replica-root: dc=lin,dc=test,dc=lan o=ipaca add nsslapd-topo-plugin-shared-binddngroup: cn=replication managers,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan add nsslapd-topo-plugin-startup-delay: 20 add nsslapd-pluginId: none add nsslapd-plugin-depends-on-named: ldbm database Multimaster Replication Plugin add nsslapd-pluginVersion: 1.0 add nsslapd-pluginVendor: none add nsslapd-pluginDescription: none adding new entry "cn=IPA Topology Configuration,cn=plugins,cn=config" modify complete 2020-06-17T10:06:14Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:14Z DEBUG step duration: dirsrv __config_topology_module 0.02 sec 2020-06-17T10:06:14Z DEBUG [19/44]: creating indices 2020-06-17T10:06:14Z DEBUG Starting external process 2020-06-17T10:06:14Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/indices.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:15Z DEBUG Process finished, return code=0 2020-06-17T10:06:15Z DEBUG stdout=add objectClass: top nsIndex add cn: krbPrincipalName add nsSystemIndex: false add nsIndexType: eq sub add nsMatchingRule: caseIgnoreIA5Match caseExactIA5Match adding new entry "cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: ou add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=ou,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: carLicense add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=carLicense,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: title add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=title,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: manager add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: secretary add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: displayname add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=displayname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add nsIndexType: sub modifying entry "cn=uid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: uidnumber add nsSystemIndex: false add nsIndexType: eq add nsMatchingRule: integerOrderingMatch adding new entry "cn=uidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: gidnumber add nsSystemIndex: false add nsIndexType: eq add nsMatchingRule: integerOrderingMatch adding new entry "cn=gidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete replace nsIndexType: eq pres modifying entry "cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete replace nsIndexType: eq pres modifying entry "cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add ObjectClass: top nsIndex add cn: fqdn add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add ObjectClass: top nsIndex add cn: macAddress add nsSystemIndex: false add nsIndexType: eq pres adding new entry "cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberHost add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberUser add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: sourcehost add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberservice add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: managedby add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberallowcmd add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberdenycmd add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipasudorunas add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipasudorunasgroup add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: automountkey add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres adding new entry "cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: automountMapName add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=automountMapName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipaConfigString add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=ipaConfigString,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipaEnabledFlag add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=ipaEnabledFlag,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipaKrbAuthzData add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=ipaKrbAuthzData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipakrbprincipalalias add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipauniqueid add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipaMemberCa add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipaMemberCertProfile add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: userCertificate add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres adding new entry "cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipalocation add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres adding new entry "cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: krbCanonicalName add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: serverhostname add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: description add objectClass: top nsindex add nssystemindex: false add nsindextype: eq sub adding new entry "cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: l add objectClass: top nsindex add nssystemindex: false add nsindextype: eq sub adding new entry "cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: nsOsVersion add objectClass: top nsindex add nssystemindex: false add nsindextype: eq sub adding new entry "cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: nsHardwarePlatform add objectClass: top nsindex add nssystemindex: false add nsindextype: eq sub adding new entry "cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: nsHostLocation add objectClass: top nsindex add nssystemindex: false add nsindextype: eq sub adding new entry "cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipServicePort add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=ipServicePort,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: accessRuleType add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=accessRuleType,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: hostCategory add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=hostCategory,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: idnsName add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=idnsName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipaCertmapData add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=ipaCertmapData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: altSecurityIdentities add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=altSecurityIdentities,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberManager add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres adding new entry "cn=memberManager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete 2020-06-17T10:06:15Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:15Z DEBUG step duration: dirsrv __create_indices 0.18 sec 2020-06-17T10:06:15Z DEBUG [20/44]: enabling referential integrity plugin 2020-06-17T10:06:15Z DEBUG Starting external process 2020-06-17T10:06:15Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/referint-conf.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:15Z DEBUG Process finished, return code=0 2020-06-17T10:06:15Z DEBUG stdout=replace nsslapd-pluginenabled: on modifying entry "cn=referential integrity postoperation,cn=plugins,cn=config" modify complete 2020-06-17T10:06:15Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:15Z DEBUG step duration: dirsrv __add_referint_module 0.02 sec 2020-06-17T10:06:15Z DEBUG [21/44]: configuring certmap.conf 2020-06-17T10:06:15Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:06:15Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:06:15Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:06:15Z DEBUG step duration: dirsrv __certmap_conf 0.00 sec 2020-06-17T10:06:15Z DEBUG [22/44]: configure new location for managed entries 2020-06-17T10:06:15Z DEBUG Starting external process 2020-06-17T10:06:15Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpy4d4i0mc', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:15Z DEBUG Process finished, return code=0 2020-06-17T10:06:15Z DEBUG stdout=add nsslapd-pluginConfigArea: cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan modifying entry "cn=Managed Entries,cn=plugins,cn=config" modify complete 2020-06-17T10:06:15Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:15Z DEBUG step duration: dirsrv __repoint_managed_entries 0.02 sec 2020-06-17T10:06:15Z DEBUG [23/44]: configure dirsrv ccache and keytab 2020-06-17T10:06:15Z DEBUG Starting external process 2020-06-17T10:06:15Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T10:06:15Z DEBUG Process finished, return code=0 2020-06-17T10:06:15Z DEBUG stdout= 2020-06-17T10:06:15Z DEBUG stderr= 2020-06-17T10:06:15Z DEBUG Starting external process 2020-06-17T10:06:15Z DEBUG args=['/sbin/restorecon', '/etc/systemd/system/dirsrv@LIN-TEST-LAN.service.d/ipa-env.conf'] 2020-06-17T10:06:15Z DEBUG Process finished, return code=0 2020-06-17T10:06:15Z DEBUG stdout= 2020-06-17T10:06:15Z DEBUG stderr= 2020-06-17T10:06:15Z DEBUG Starting external process 2020-06-17T10:06:15Z DEBUG args=['/bin/systemctl', '--system', 'daemon-reload'] 2020-06-17T10:06:15Z DEBUG Process finished, return code=0 2020-06-17T10:06:15Z DEBUG stdout= 2020-06-17T10:06:15Z DEBUG stderr= 2020-06-17T10:06:15Z DEBUG step duration: dirsrv configure_systemd_ipa_env 0.20 sec 2020-06-17T10:06:15Z DEBUG [24/44]: enabling SASL mapping fallback 2020-06-17T10:06:15Z DEBUG Starting external process 2020-06-17T10:06:15Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpmbgrrk91', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:15Z DEBUG Process finished, return code=0 2020-06-17T10:06:15Z DEBUG stdout=replace nsslapd-sasl-mapping-fallback: on modifying entry "cn=config" modify complete 2020-06-17T10:06:15Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:15Z DEBUG step duration: dirsrv __enable_sasl_mapping_fallback 0.02 sec 2020-06-17T10:06:15Z DEBUG [25/44]: restarting directory server 2020-06-17T10:06:15Z DEBUG Destroyed connection context.ldap2_139850008098072 2020-06-17T10:06:15Z DEBUG Starting external process 2020-06-17T10:06:15Z DEBUG args=['/bin/systemctl', '--system', 'daemon-reload'] 2020-06-17T10:06:15Z DEBUG Process finished, return code=0 2020-06-17T10:06:15Z DEBUG stdout= 2020-06-17T10:06:15Z DEBUG stderr= 2020-06-17T10:06:15Z DEBUG Starting external process 2020-06-17T10:06:15Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:06:18Z DEBUG Process finished, return code=0 2020-06-17T10:06:18Z DEBUG stdout= 2020-06-17T10:06:18Z DEBUG stderr= 2020-06-17T10:06:18Z DEBUG Starting external process 2020-06-17T10:06:18Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:06:18Z DEBUG Process finished, return code=0 2020-06-17T10:06:18Z DEBUG stdout=active 2020-06-17T10:06:18Z DEBUG stderr= 2020-06-17T10:06:18Z DEBUG wait_for_open_ports: localhost [389] timeout 120 2020-06-17T10:06:18Z DEBUG waiting for port: 389 2020-06-17T10:06:18Z DEBUG SUCCESS: port: 389 2020-06-17T10:06:18Z DEBUG Restart of dirsrv@LIN-TEST-LAN.service complete 2020-06-17T10:06:18Z DEBUG Starting external process 2020-06-17T10:06:18Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:06:18Z DEBUG Process finished, return code=0 2020-06-17T10:06:18Z DEBUG stdout=active 2020-06-17T10:06:18Z DEBUG stderr= 2020-06-17T10:06:18Z DEBUG Created connection context.ldap2_139850008098072 2020-06-17T10:06:18Z DEBUG step duration: dirsrv __restart_instance 3.14 sec 2020-06-17T10:06:18Z DEBUG [26/44]: adding sasl mappings to the directory 2020-06-17T10:06:18Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:06:18Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:06:18Z DEBUG step duration: dirsrv __configure_sasl_mappings 0.23 sec 2020-06-17T10:06:18Z DEBUG [27/44]: adding default layout 2020-06-17T10:06:18Z DEBUG Starting external process 2020-06-17T10:06:18Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp8ii24tbp', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:19Z DEBUG Process finished, return code=0 2020-06-17T10:06:19Z DEBUG stdout=add objectClass: top nsContainer add cn: accounts adding new entry "cn=accounts,dc=lin,dc=test,dc=lan" modify complete add objectClass: top nsContainer add cn: users adding new entry "cn=users,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add objectClass: top nsContainer add cn: groups adding new entry "cn=groups,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add objectClass: top nsContainer add cn: services adding new entry "cn=services,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add objectClass: top nsContainer add cn: computers adding new entry "cn=computers,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add objectClass: top nsContainer add cn: hostgroups adding new entry "cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add objectClass: top nsContainer add cn: ipservices adding new entry "cn=ipservices,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer add cn: alt adding new entry "cn=alt,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer add cn: ng adding new entry "cn=ng,cn=alt,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer add cn: automount adding new entry "cn=automount,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer add cn: default adding new entry "cn=default,cn=automount,dc=lin,dc=test,dc=lan" modify complete add objectClass: automountMap add automountMapName: auto.master adding new entry "automountmapname=auto.master,cn=default,cn=automount,dc=lin,dc=test,dc=lan" modify complete add objectClass: automountMap add automountMapName: auto.direct adding new entry "automountmapname=auto.direct,cn=default,cn=automount,dc=lin,dc=test,dc=lan" modify complete add objectClass: automount add automountKey: /- add automountInformation: auto.direct add description: /- auto.direct adding new entry "description=/- auto.direct,automountmapname=auto.master,cn=default,cn=automount,dc=lin,dc=test,dc=lan" modify complete add objectClass: top nsContainer add cn: hbac adding new entry "cn=hbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top nsContainer add cn: hbacservices adding new entry "cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top nsContainer add cn: hbacservicegroups adding new entry "cn=hbacservicegroups,cn=hbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top nsContainer add cn: sudo adding new entry "cn=sudo,dc=lin,dc=test,dc=lan" modify complete add objectClass: top nsContainer add cn: sudocmds adding new entry "cn=sudocmds,cn=sudo,dc=lin,dc=test,dc=lan" modify complete add objectClass: top nsContainer add cn: sudocmdgroups adding new entry "cn=sudocmdgroups,cn=sudo,dc=lin,dc=test,dc=lan" modify complete add objectClass: top nsContainer add cn: sudorules adding new entry "cn=sudorules,cn=sudo,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top add cn: etc adding new entry "cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top add cn: locations adding new entry "cn=locations,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top add cn: sysaccounts adding new entry "cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top add cn: ipa adding new entry "cn=ipa,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top add cn: masters adding new entry "cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top add cn: replicas adding new entry "cn=replicas,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top add cn: dna adding new entry "cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top add cn: posix-ids adding new entry "cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top add cn: ca_renewal adding new entry "cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top add cn: certificates adding new entry "cn=certificates,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top add cn: custodia adding new entry "cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top add cn: dogtag adding new entry "cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top add cn: s4u2proxy adding new entry "cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectClass: ipaKrb5DelegationACL groupOfPrincipals top add cn: ipa-http-delegation add memberPrincipal: HTTP/freeipaserver.lin.test.lan@LIN.TEST.LAN add ipaAllowedTarget: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan adding new entry "cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectClass: groupOfPrincipals top add cn: ipa-ldap-delegation-targets add memberPrincipal: ldap/freeipaserver.lin.test.lan@LIN.TEST.LAN adding new entry "cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectClass: groupOfPrincipals top add cn: ipa-cifs-delegation-targets adding new entry "cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectClass: top person posixaccount krbprincipalaux krbticketpolicyaux inetuser ipaobject ipasshuser add uid: admin add krbPrincipalName: admin@LIN.TEST.LAN add cn: Administrator add sn: Administrator add uidNumber: 363600000 add gidNumber: 363600000 add homeDirectory: /home/admin add loginShell: /bin/bash add gecos: Administrator add nsAccountLock: FALSE add ipaUniqueID: autogenerate adding new entry "uid=admin,cn=users,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames posixgroup ipausergroup ipaobject add cn: admins add description: Account administrators group add gidNumber: 363600000 add member: uid=admin,cn=users,cn=accounts,dc=lin,dc=test,dc=lan add nsAccountLock: FALSE add ipaUniqueID: autogenerate adding new entry "cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames nestedgroup ipausergroup ipaobject add description: Default group for all users add cn: ipausers add ipaUniqueID: autogenerate adding new entry "cn=ipausers,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames posixgroup ipausergroup ipaobject add gidNumber: 363600002 add description: Limited admins who can edit other users add cn: editors add ipaUniqueID: autogenerate adding new entry "cn=editors,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupOfNames nestedGroup ipaobject ipahostgroup add description: IPA server hosts add cn: ipaservers add ipaUniqueID: autogenerate adding new entry "cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add objectclass: ipahbacservice ipaobject add cn: sshd add description: sshd add ipauniqueid: autogenerate adding new entry "cn=sshd,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan" modify complete add objectclass: ipahbacservice ipaobject add cn: ftp add description: ftp add ipauniqueid: autogenerate adding new entry "cn=ftp,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan" modify complete add objectclass: ipahbacservice ipaobject add cn: su add description: su add ipauniqueid: autogenerate adding new entry "cn=su,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan" modify complete add objectclass: ipahbacservice ipaobject add cn: login add description: login add ipauniqueid: autogenerate adding new entry "cn=login,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan" modify complete add objectclass: ipahbacservice ipaobject add cn: su-l add description: su with login shell add ipauniqueid: autogenerate adding new entry "cn=su-l,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan" modify complete add objectclass: ipahbacservice ipaobject add cn: sudo add description: sudo add ipauniqueid: autogenerate adding new entry "cn=sudo,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan" modify complete add objectclass: ipahbacservice ipaobject add cn: sudo-i add description: sudo-i add ipauniqueid: autogenerate adding new entry "cn=sudo-i,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan" modify complete add objectclass: ipahbacservice ipaobject add cn: systemd-user add description: pam_systemd and systemd user@.service add ipauniqueid: autogenerate adding new entry "cn=systemd-user,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan" modify complete add objectclass: ipahbacservice ipaobject add cn: gdm add description: gdm add ipauniqueid: autogenerate adding new entry "cn=gdm,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan" modify complete add objectclass: ipahbacservice ipaobject add cn: gdm-password add description: gdm-password add ipauniqueid: autogenerate adding new entry "cn=gdm-password,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan" modify complete add objectclass: ipahbacservice ipaobject add cn: kdm add description: kdm add ipauniqueid: autogenerate adding new entry "cn=kdm,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: ipaobject ipahbacservicegroup nestedGroup groupOfNames top add cn: Sudo add ipauniqueid: autogenerate add description: Default group of Sudo related services add member: cn=sudo,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan cn=sudo-i,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan adding new entry "cn=Sudo,cn=hbacservicegroups,cn=hbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top ipaGuiConfig ipaConfigObject add ipaUserSearchFields: uid,givenname,sn,telephonenumber,ou,title add ipaGroupSearchFields: cn,description add ipaSearchTimeLimit: 2 add ipaSearchRecordsLimit: 100 add ipaHomesRootDir: /home add ipaDefaultLoginShell: /bin/sh add ipaDefaultPrimaryGroup: ipausers add ipaMaxUsernameLength: 32 add ipaMaxHostnameLength: 64 add ipaPwdExpAdvNotify: 4 add ipaGroupObjectClasses: top groupofnames nestedgroup ipausergroup ipaobject add ipaUserObjectClasses: top person organizationalperson inetorgperson inetuser posixaccount krbprincipalaux krbticketpolicyaux ipaobject ipasshuser add ipaDefaultEmailDomain: lin.test.lan add ipaMigrationEnabled: FALSE add ipaConfigString: AllowNThash KDC:Disable Last Success add ipaSELinuxUserMapOrder: guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$sysadm_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 add ipaSELinuxUserMapDefault: unconfined_u:s0-s0:c0.c1023 adding new entry "cn=ipaConfig,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectclass: top nsContainer add cn: cosTemplates adding new entry "cn=cosTemplates,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add description: Password Policy based on group membership add objectClass: top ldapsubentry cosSuperDefinition cosClassicDefinition add cosTemplateDn: cn=cosTemplates,cn=accounts,dc=lin,dc=test,dc=lan add cosAttribute: krbPwdPolicyReference override add cosSpecifier: memberOf adding new entry "cn=Password Policy,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add objectClass: top nsContainer add cn: selinux adding new entry "cn=selinux,dc=lin,dc=test,dc=lan" modify complete add objectClass: top nsContainer add cn: usermap adding new entry "cn=usermap,cn=selinux,dc=lin,dc=test,dc=lan" modify complete add objectClass: top nsContainer add cn: ranges adding new entry "cn=ranges,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectClass: top ipaIDrange ipaDomainIDRange add cn: LIN.TEST.LAN_id_range add ipaBaseID: 363600000 add ipaIDRangeSize: 200000 add ipaRangeType: ipa-local adding new entry "cn=LIN.TEST.LAN_id_range,cn=ranges,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top add cn: ca adding new entry "cn=ca,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top add cn: certprofiles adding new entry "cn=certprofiles,cn=ca,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top add cn: caacls adding new entry "cn=caacls,cn=ca,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top add cn: cas adding new entry "cn=cas,cn=ca,dc=lin,dc=test,dc=lan" modify complete 2020-06-17T10:06:19Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:19Z DEBUG step duration: dirsrv __add_default_layout 0.39 sec 2020-06-17T10:06:19Z DEBUG [28/44]: adding delegation layout 2020-06-17T10:06:19Z DEBUG Starting external process 2020-06-17T10:06:19Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp12cz_eun', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:19Z DEBUG Process finished, return code=0 2020-06-17T10:06:19Z DEBUG stdout=add objectClass: top nsContainer add cn: roles adding new entry "cn=roles,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add objectClass: top nsContainer add cn: pbac adding new entry "cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top nsContainer add cn: privileges adding new entry "cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top nsContainer add cn: permissions adding new entry "cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames nestedgroup add cn: helpdesk add description: Helpdesk adding new entry "cn=helpdesk,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames nestedgroup add cn: User Administrators add description: User Administrators adding new entry "cn=User Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames nestedgroup add cn: Group Administrators add description: Group Administrators adding new entry "cn=Group Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames nestedgroup add cn: Host Administrators add description: Host Administrators adding new entry "cn=Host Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames nestedgroup add cn: Host Group Administrators add description: Host Group Administrators adding new entry "cn=Host Group Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames nestedgroup add cn: Delegation Administrator add description: Role administration adding new entry "cn=Delegation Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames nestedgroup add cn: DNS Administrators add description: DNS Administrators adding new entry "cn=DNS Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames nestedgroup add cn: DNS Servers add description: DNS Servers adding new entry "cn=DNS Servers,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames nestedgroup add cn: Service Administrators add description: Service Administrators adding new entry "cn=Service Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames nestedgroup add cn: Automount Administrators add description: Automount Administrators adding new entry "cn=Automount Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames nestedgroup add cn: Netgroups Administrators add description: Netgroups Administrators adding new entry "cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames nestedgroup add cn: Certificate Administrators add description: Certificate Administrators adding new entry "cn=Certificate Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames nestedgroup add cn: Replication Administrators add description: Replication Administrators add member: cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan adding new entry "cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames nestedgroup add cn: Host Enrollment add description: Host Enrollment adding new entry "cn=Host Enrollment,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames nestedgroup add cn: Stage User Administrators add description: Stage User Administrators adding new entry "cn=Stage User Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames nestedgroup add cn: Stage User Provisioning add description: Stage User Provisioning adding new entry "cn=Stage User Provisioning,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames ipapermission add cn: Add Replication Agreements add ipapermissiontype: SYSTEM add member: cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan adding new entry "cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames ipapermission add cn: Modify Replication Agreements add ipapermissiontype: SYSTEM add member: cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan adding new entry "cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames ipapermission add cn: Read Replication Agreements add ipapermissiontype: SYSTEM add member: cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan adding new entry "cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames ipapermission add cn: Remove Replication Agreements add ipapermissiontype: SYSTEM add member: cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan adding new entry "cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames ipapermission add cn: Modify DNA Range add ipapermissiontype: SYSTEM add member: cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan adding new entry "cn=Modify DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add objectClass: top nsContainer add cn: virtual operations adding new entry "cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames ipapermission add cn: Retrieve Certificates from the CA add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan adding new entry "cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) modifying entry "dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames ipapermission add cn: Request Certificate add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan adding new entry "cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) modifying entry "dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames ipapermission add cn: Request Certificates from a different host add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan adding new entry "cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) modifying entry "dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames ipapermission add cn: Get Certificates status from the CA add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan adding new entry "cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) modifying entry "dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames ipapermission add cn: Revoke Certificate add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan adding new entry "cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) modifying entry "dc=lin,dc=test,dc=lan" modify complete add objectClass: top groupofnames ipapermission add cn: Certificate Remove Hold add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan adding new entry "cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) modifying entry "dc=lin,dc=test,dc=lan" modify complete 2020-06-17T10:06:19Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:19Z DEBUG step duration: dirsrv __add_delegation_layout 0.21 sec 2020-06-17T10:06:19Z DEBUG [29/44]: creating container for managed entries 2020-06-17T10:06:19Z DEBUG Starting external process 2020-06-17T10:06:19Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpqt7rgx5g', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:19Z DEBUG Process finished, return code=0 2020-06-17T10:06:19Z DEBUG stdout=add objectClass: nsContainer top add cn: Managed Entries adding new entry "cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top add cn: Templates adding new entry "cn=Templates,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top add cn: Definitions adding new entry "cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan" modify complete 2020-06-17T10:06:19Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:19Z DEBUG step duration: dirsrv __managed_entries 0.02 sec 2020-06-17T10:06:19Z DEBUG [30/44]: configuring user private groups 2020-06-17T10:06:19Z DEBUG Starting external process 2020-06-17T10:06:19Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpn_w9nb2x', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:19Z DEBUG Process finished, return code=0 2020-06-17T10:06:19Z DEBUG stdout=add objectclass: mepTemplateEntry add cn: UPG Template add mepRDNAttr: cn add mepStaticAttr: objectclass: posixgroup objectclass: ipaobject ipaUniqueId: autogenerate add mepMappedAttr: cn: $uid gidNumber: $uidNumber description: User private group for $uid adding new entry "cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectclass: extensibleObject add cn: UPG Definition add originScope: cn=users,cn=accounts,dc=lin,dc=test,dc=lan add originFilter: (&(objectclass=posixAccount)(!(description=__no_upg__))) add managedBase: cn=groups,cn=accounts,dc=lin,dc=test,dc=lan add managedTemplate: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan adding new entry "cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan" modify complete 2020-06-17T10:06:19Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:19Z DEBUG step duration: dirsrv __user_private_groups 0.02 sec 2020-06-17T10:06:19Z DEBUG [31/44]: configuring netgroups from hostgroups 2020-06-17T10:06:19Z DEBUG Starting external process 2020-06-17T10:06:19Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpn8cmyvvp', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:19Z DEBUG Process finished, return code=0 2020-06-17T10:06:19Z DEBUG stdout=add objectclass: mepTemplateEntry add cn: NGP HGP Template add mepRDNAttr: cn add mepStaticAttr: ipaUniqueId: autogenerate objectclass: ipanisnetgroup objectclass: ipaobject nisDomainName: lin.test.lan add mepMappedAttr: cn: $cn memberHost: $dn description: ipaNetgroup $cn adding new entry "cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectclass: extensibleObject add cn: NGP Definition add originScope: cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan add originFilter: objectclass=ipahostgroup add managedBase: cn=ng,cn=alt,dc=lin,dc=test,dc=lan add managedTemplate: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan adding new entry "cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan" modify complete 2020-06-17T10:06:19Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:19Z DEBUG step duration: dirsrv __host_nis_groups 0.02 sec 2020-06-17T10:06:19Z DEBUG [32/44]: creating default Sudo bind user 2020-06-17T10:06:19Z DEBUG Starting external process 2020-06-17T10:06:19Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp1o0ubg_w', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:19Z DEBUG Process finished, return code=0 2020-06-17T10:06:19Z DEBUG stdout=add objectclass: account simplesecurityobject add uid: sudo add userPassword: XXXXXXXX add passwordExpirationTime: 20380119031407Z add nsIdleTimeout: 0 adding new entry "uid=sudo,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan" modify complete 2020-06-17T10:06:19Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:19Z DEBUG step duration: dirsrv __add_sudo_binduser 0.05 sec 2020-06-17T10:06:19Z DEBUG [33/44]: creating default Auto Member layout 2020-06-17T10:06:19Z DEBUG Starting external process 2020-06-17T10:06:19Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpdds32411', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:19Z DEBUG Process finished, return code=0 2020-06-17T10:06:19Z DEBUG stdout=add nsslapd-pluginConfigArea: cn=automember,cn=etc,dc=lin,dc=test,dc=lan modifying entry "cn=Auto Membership Plugin,cn=plugins,cn=config" modify complete add objectClass: top nsContainer add cn: automember adding new entry "cn=automember,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectclass: autoMemberDefinition add cn: Hostgroup add autoMemberScope: cn=computers,cn=accounts,dc=lin,dc=test,dc=lan add autoMemberFilter: objectclass=ipaHost add autoMemberGroupingAttr: member:dn adding new entry "cn=Hostgroup,cn=automember,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectclass: autoMemberDefinition add cn: Group add autoMemberScope: cn=users,cn=accounts,dc=lin,dc=test,dc=lan add autoMemberFilter: objectclass=posixAccount add autoMemberGroupingAttr: member:dn adding new entry "cn=Group,cn=automember,cn=etc,dc=lin,dc=test,dc=lan" modify complete 2020-06-17T10:06:19Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:19Z DEBUG step duration: dirsrv __add_automember_config 0.03 sec 2020-06-17T10:06:19Z DEBUG [34/44]: adding range check plugin 2020-06-17T10:06:19Z DEBUG Starting external process 2020-06-17T10:06:19Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpggr1tt_4', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:19Z DEBUG Process finished, return code=0 2020-06-17T10:06:19Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA Range-Check add nsslapd-pluginpath: libipa_range_check add nsslapd-plugininitfunc: ipa_range_check_init add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_range_check_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA Range-Check plugin add nsslapd-plugin-depends-on-type: database add nsslapd-basedn: dc=lin,dc=test,dc=lan adding new entry "cn=IPA Range-Check,cn=plugins,cn=config" modify complete 2020-06-17T10:06:19Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:19Z DEBUG step duration: dirsrv __add_range_check_plugin 0.02 sec 2020-06-17T10:06:19Z DEBUG [35/44]: creating default HBAC rule allow_all 2020-06-17T10:06:19Z DEBUG Starting external process 2020-06-17T10:06:19Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp41piulf7', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:19Z DEBUG Process finished, return code=0 2020-06-17T10:06:19Z DEBUG stdout=add objectclass: ipaassociation ipahbacrule add cn: allow_all add accessruletype: allow add usercategory: all add hostcategory: all add servicecategory: all add ipaenabledflag: TRUE add description: Allow all users to access any host from any host add ipauniqueid: autogenerate adding new entry "ipauniqueid=autogenerate,cn=hbac,dc=lin,dc=test,dc=lan" modify complete add objectclass: ipaassociation ipahbacrule add cn: allow_systemd-user add accessruletype: allow add usercategory: all add hostcategory: all add memberService: cn=systemd-user,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan add ipaenabledflag: TRUE add description: Allow pam_systemd to run user@.service to create a system user session add ipauniqueid: autogenerate adding new entry "ipauniqueid=autogenerate,cn=hbac,dc=lin,dc=test,dc=lan" modify complete 2020-06-17T10:06:19Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:19Z DEBUG step duration: dirsrv add_hbac 0.06 sec 2020-06-17T10:06:19Z DEBUG [36/44]: adding entries for topology management 2020-06-17T10:06:19Z DEBUG Starting external process 2020-06-17T10:06:19Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpgnmqcu1v', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:19Z DEBUG Process finished, return code=0 2020-06-17T10:06:19Z DEBUG stdout=add objectclass: top nsContainer add cn: topology adding new entry "cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan" modify complete add objectclass: top iparepltopoconf add ipaReplTopoConfRoot: dc=lin,dc=test,dc=lan add nsDS5ReplicatedAttributeList: (objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount add nsDS5ReplicatedAttributeListTotal: (objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount add nsds5ReplicaStripAttrs: modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp add cn: domain adding new entry "cn=domain,cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan" modify complete 2020-06-17T10:06:19Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:19Z DEBUG step duration: dirsrv __add_topology_entries 0.02 sec 2020-06-17T10:06:19Z DEBUG [37/44]: initializing group membership 2020-06-17T10:06:19Z DEBUG Starting external process 2020-06-17T10:06:19Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpdo2otipn', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:19Z DEBUG Process finished, return code=0 2020-06-17T10:06:19Z DEBUG stdout=add objectClass: top extensibleObject add cn: IPA install add basedn: dc=lin,dc=test,dc=lan add filter: (objectclass=*) add ttl: 10 adding new entry "cn=IPA install 1592388359, cn=memberof task, cn=tasks, cn=config" modify complete 2020-06-17T10:06:19Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:19Z DEBUG Waiting for memberof task to complete. 2020-06-17T10:06:20Z DEBUG step duration: dirsrv init_memberof 1.02 sec 2020-06-17T10:06:20Z DEBUG [38/44]: adding master entry 2020-06-17T10:06:20Z DEBUG Starting external process 2020-06-17T10:06:20Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmppa_1ro2_', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:20Z DEBUG Process finished, return code=0 2020-06-17T10:06:20Z DEBUG stdout=add objectclass: top nsContainer ipaReplTopoManagedServer ipaConfigObject ipaSupportedDomainLevelConfig add cn: freeipaserver.lin.test.lan add ipaReplTopoManagedSuffix: dc=lin,dc=test,dc=lan add ipaMinDomainLevel: 1 add ipaMaxDomainLevel: 1 adding new entry "cn=freeipaserver.lin.test.lan,cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan" modify complete 2020-06-17T10:06:20Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:20Z DEBUG step duration: dirsrv __add_master_entry 0.01 sec 2020-06-17T10:06:20Z DEBUG [39/44]: initializing domain level 2020-06-17T10:06:20Z DEBUG Starting external process 2020-06-17T10:06:20Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp_3eyo09f', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:20Z DEBUG Process finished, return code=0 2020-06-17T10:06:20Z DEBUG stdout=add objectClass: top nsContainer ipaDomainLevelConfig add ipaDomainLevel: 1 adding new entry "cn=Domain Level,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan" modify complete 2020-06-17T10:06:20Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:20Z DEBUG step duration: dirsrv __set_domain_level 0.02 sec 2020-06-17T10:06:20Z DEBUG [40/44]: configuring Posix uid/gid generation 2020-06-17T10:06:20Z DEBUG Starting external process 2020-06-17T10:06:20Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp1h5vrgsg', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:20Z DEBUG Process finished, return code=0 2020-06-17T10:06:20Z DEBUG stdout=add objectclass: top extensibleObject add cn: Posix IDs add dnaType: uidNumber gidNumber add dnaNextValue: 363600000 add dnaMaxValue: 363799999 add dnaMagicRegen: -1 add dnaFilter: (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) add dnaScope: dc=lin,dc=test,dc=lan add dnaThreshold: 500 add dnaSharedCfgDN: cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan add dnaExcludeScope: cn=provisioning,dc=lin,dc=test,dc=lan adding new entry "cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" modify complete replace nsslapd-pluginEnabled: on modifying entry "cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" modify complete 2020-06-17T10:06:20Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:20Z DEBUG step duration: dirsrv __config_uidgid_gen 0.02 sec 2020-06-17T10:06:20Z DEBUG [41/44]: adding replication acis 2020-06-17T10:06:20Z DEBUG Starting external process 2020-06-17T10:06:20Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpm45naf19', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:20Z DEBUG Process finished, return code=0 2020-06-17T10:06:20Z DEBUG stdout=add aci: (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) modifying entry "cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" modify complete add aci: (targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) modifying entry "cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add aci: (targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) modifying entry "cn=tasks,cn=config" modify complete 2020-06-17T10:06:20Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:20Z DEBUG step duration: dirsrv __add_replication_acis 0.04 sec 2020-06-17T10:06:20Z DEBUG [42/44]: activating sidgen plugin 2020-06-17T10:06:20Z DEBUG Starting external process 2020-06-17T10:06:20Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpl1a9bw1_', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:20Z DEBUG Process finished, return code=0 2020-06-17T10:06:20Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA SIDGEN add nsslapd-pluginpath: libipa_sidgen add nsslapd-plugininitfunc: ipa_sidgen_init add nsslapd-plugintype: postoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_sidgen_postop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA SIDGEN post operation add nsslapd-plugin-depends-on-type: database add nsslapd-basedn: dc=lin,dc=test,dc=lan adding new entry "cn=IPA SIDGEN,cn=plugins,cn=config" modify complete 2020-06-17T10:06:20Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:20Z DEBUG step duration: dirsrv _add_sidgen_plugin 0.02 sec 2020-06-17T10:06:20Z DEBUG [43/44]: activating extdom plugin 2020-06-17T10:06:20Z DEBUG Starting external process 2020-06-17T10:06:20Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpobnsv65q', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:20Z DEBUG Process finished, return code=0 2020-06-17T10:06:20Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa_extdom_extop add nsslapd-pluginpath: libipa_extdom_extop add nsslapd-plugininitfunc: ipa_extdom_init add nsslapd-plugintype: extendedop add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_extdom_extop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: RedHat add nsslapd-plugindescription: Support resolving IDs in trusted domains to names and back add nsslapd-plugin-depends-on-type: database add nsslapd-basedn: dc=lin,dc=test,dc=lan adding new entry "cn=ipa_extdom_extop,cn=plugins,cn=config" modify complete 2020-06-17T10:06:20Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:20Z DEBUG step duration: dirsrv _add_extdom_plugin 0.02 sec 2020-06-17T10:06:20Z DEBUG [44/44]: configuring directory to start on boot 2020-06-17T10:06:20Z DEBUG Starting external process 2020-06-17T10:06:20Z DEBUG args=['/bin/systemctl', 'is-enabled', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:06:20Z DEBUG Process finished, return code=0 2020-06-17T10:06:20Z DEBUG stdout=enabled 2020-06-17T10:06:20Z DEBUG stderr= 2020-06-17T10:06:20Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:20Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:20Z DEBUG Starting external process 2020-06-17T10:06:20Z DEBUG args=['/bin/systemctl', 'disable', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:06:20Z DEBUG Process finished, return code=0 2020-06-17T10:06:20Z DEBUG stdout= 2020-06-17T10:06:20Z DEBUG stderr=Removed /etc/systemd/system/multi-user.target.wants/dirsrv@LIN-TEST-LAN.service. Removed /etc/systemd/system/dirsrv.target.wants/dirsrv@LIN-TEST-LAN.service. 2020-06-17T10:06:20Z DEBUG step duration: dirsrv __enable 0.17 sec 2020-06-17T10:06:20Z DEBUG Done configuring directory server (dirsrv). 2020-06-17T10:06:20Z DEBUG service duration: dirsrv 21.82 sec 2020-06-17T10:06:20Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:20Z DEBUG Starting external process 2020-06-17T10:06:20Z DEBUG args=['/bin/keyctl', 'get_persistent', '@s', '0'] 2020-06-17T10:06:20Z DEBUG Process finished, return code=0 2020-06-17T10:06:20Z DEBUG stdout=911560679 2020-06-17T10:06:20Z DEBUG stderr= 2020-06-17T10:06:20Z DEBUG Enabling persistent keyring CCACHE 2020-06-17T10:06:20Z DEBUG Starting external process 2020-06-17T10:06:20Z DEBUG args=['/bin/systemctl', 'is-active', 'krb5kdc.service'] 2020-06-17T10:06:20Z DEBUG Process finished, return code=3 2020-06-17T10:06:20Z DEBUG stdout=inactive 2020-06-17T10:06:20Z DEBUG stderr= 2020-06-17T10:06:20Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:20Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:20Z DEBUG Starting external process 2020-06-17T10:06:20Z DEBUG args=['/bin/systemctl', 'stop', 'krb5kdc.service'] 2020-06-17T10:06:20Z DEBUG Process finished, return code=0 2020-06-17T10:06:20Z DEBUG stdout= 2020-06-17T10:06:20Z DEBUG stderr= 2020-06-17T10:06:20Z DEBUG Stop of krb5kdc.service complete 2020-06-17T10:06:20Z DEBUG Configuring Kerberos KDC (krb5kdc) 2020-06-17T10:06:20Z DEBUG [1/10]: adding kerberos container to the directory 2020-06-17T10:06:20Z DEBUG Starting external process 2020-06-17T10:06:20Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp7449_84m', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:20Z DEBUG Process finished, return code=0 2020-06-17T10:06:20Z DEBUG stdout=add objectClass: krbContainer top add cn: kerberos adding new entry "cn=kerberos,dc=lin,dc=test,dc=lan" modify complete add cn: LIN.TEST.LAN add objectClass: top krbrealmcontainer krbticketpolicyaux add krbSubTrees: dc=lin,dc=test,dc=lan add krbSearchScope: 2 add krbSupportedEncSaltTypes: aes256-cts:normal aes256-cts:special aes128-cts:normal aes128-cts:special aes128-sha2:normal aes128-sha2:special aes256-sha2:normal aes256-sha2:special camellia128-cts-cmac:normal camellia128-cts-cmac:special camellia256-cts-cmac:normal camellia256-cts-cmac:special add krbMaxTicketLife: 86400 add krbMaxRenewableAge: 604800 add krbDefaultEncSaltTypes: aes256-cts:special aes128-cts:special adding new entry "cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan" modify complete add objectClass: top nsContainer krbPwdPolicy add krbMinPwdLife: 3600 add krbPwdMinDiffChars: 0 add krbPwdMinLength: 8 add krbPwdHistoryLength: 0 add krbMaxPwdLife: 7776000 add krbPwdMaxFailure: 6 add krbPwdFailureCountInterval: 60 add krbPwdLockoutDuration: 600 adding new entry "cn=global_policy,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan" modify complete 2020-06-17T10:06:20Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:20Z DEBUG step duration: krb5kdc __add_krb_container 0.02 sec 2020-06-17T10:06:20Z DEBUG [2/10]: configuring KDC 2020-06-17T10:06:20Z DEBUG Backing up system configuration file '/var/kerberos/krb5kdc/kdc.conf' 2020-06-17T10:06:20Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:06:20Z DEBUG Backing up system configuration file '/etc/krb5.conf' 2020-06-17T10:06:20Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:06:20Z DEBUG Backing up system configuration file '/etc/krb5.conf.d/freeipa-server' 2020-06-17T10:06:20Z DEBUG -> Not backing up - '/etc/krb5.conf.d/freeipa-server' doesn't exist 2020-06-17T10:06:20Z DEBUG Backing up system configuration file '/etc/krb5.conf.d/freeipa' 2020-06-17T10:06:20Z DEBUG -> Not backing up - '/etc/krb5.conf.d/freeipa' doesn't exist 2020-06-17T10:06:20Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krb5.ini' 2020-06-17T10:06:20Z DEBUG -> Not backing up - '/usr/share/ipa/html/krb5.ini' doesn't exist 2020-06-17T10:06:20Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krb.con' 2020-06-17T10:06:20Z DEBUG -> Not backing up - '/usr/share/ipa/html/krb.con' doesn't exist 2020-06-17T10:06:20Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krbrealm.con' 2020-06-17T10:06:20Z DEBUG -> Not backing up - '/usr/share/ipa/html/krbrealm.con' doesn't exist 2020-06-17T10:06:20Z DEBUG Starting external process 2020-06-17T10:06:20Z DEBUG args=['/usr/bin/klist', '-V'] 2020-06-17T10:06:20Z DEBUG Process finished, return code=0 2020-06-17T10:06:20Z DEBUG stdout=Kerberos 5 version 1.17 2020-06-17T10:06:20Z DEBUG stderr= 2020-06-17T10:06:20Z DEBUG Backing up system configuration file '/etc/sysconfig/krb5kdc' 2020-06-17T10:06:20Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:06:20Z DEBUG Starting external process 2020-06-17T10:06:20Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T10:06:20Z DEBUG Process finished, return code=0 2020-06-17T10:06:20Z DEBUG stdout= 2020-06-17T10:06:20Z DEBUG stderr= 2020-06-17T10:06:20Z DEBUG Starting external process 2020-06-17T10:06:20Z DEBUG args=['/sbin/restorecon', '/etc/sysconfig/krb5kdc'] 2020-06-17T10:06:20Z DEBUG Process finished, return code=0 2020-06-17T10:06:20Z DEBUG stdout= 2020-06-17T10:06:20Z DEBUG stderr= 2020-06-17T10:06:20Z DEBUG step duration: krb5kdc __configure_instance 0.04 sec 2020-06-17T10:06:20Z DEBUG [3/10]: initialize kerberos container 2020-06-17T10:06:20Z DEBUG Starting external process 2020-06-17T10:06:20Z DEBUG args=['kdb5_util', 'create', '-s', '-r', 'LIN.TEST.LAN', '-x', 'ipa-setup-override-restrictions'] 2020-06-17T10:06:21Z DEBUG Process finished, return code=0 2020-06-17T10:06:21Z DEBUG stdout=Loading random data Initializing database '/var/kerberos/krb5kdc/principal' for realm 'LIN.TEST.LAN', master key name 'K/M@LIN.TEST.LAN' You will be prompted for the database Master Password. It is important that you NOT FORGET this password. Enter KDC database master key: Re-enter KDC database master key to verify: 2020-06-17T10:06:21Z DEBUG stderr= 2020-06-17T10:06:21Z DEBUG step duration: krb5kdc __init_ipa_kdb 0.18 sec 2020-06-17T10:06:21Z DEBUG [4/10]: adding default ACIs 2020-06-17T10:06:21Z DEBUG Starting external process 2020-06-17T10:06:21Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpk_twmzzi', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:21Z DEBUG Process finished, return code=0 2020-06-17T10:06:21Z DEBUG stdout=add aci: (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) modifying entry "dc=lin,dc=test,dc=lan" modify complete add aci: (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) modifying entry "dc=lin,dc=test,dc=lan" modify complete add aci: (targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) modifying entry "cn=etc,dc=lin,dc=test,dc=lan" modify complete add aci: (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) modifying entry "cn=ipa,cn=etc,dc=lin,dc=test,dc=lan" modify complete add aci: (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) modifying entry "cn=accounts,dc=lin,dc=test,dc=lan" modify complete add aci: (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) modifying entry "cn=services,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add aci: (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) modifying entry "cn=services,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add aci: (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) modifying entry "cn=computers,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add aci: (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) modifying entry "cn=computers,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add aci: (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) modifying entry "cn=computers,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add aci: (targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) modifying entry "cn=groups,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add aci: (targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) modifying entry "cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" modify complete add aci: (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) modifying entry "cn=accounts,dc=lin,dc=test,dc=lan" modify complete add aci: (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) modifying entry "dc=lin,dc=test,dc=lan" modify complete 2020-06-17T10:06:21Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:21Z DEBUG step duration: krb5kdc __add_default_acis 0.05 sec 2020-06-17T10:06:21Z DEBUG [5/10]: creating a keytab for the directory 2020-06-17T10:06:21Z DEBUG Starting external process 2020-06-17T10:06:21Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'addprinc -randkey ldap/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-x', 'ipa-setup-override-restrictions'] 2020-06-17T10:06:21Z DEBUG Process finished, return code=0 2020-06-17T10:06:21Z DEBUG stdout=Authenticating as principal root/admin@LIN.TEST.LAN with password. Principal "ldap/freeipaserver.lin.test.lan@LIN.TEST.LAN" created. 2020-06-17T10:06:21Z DEBUG stderr=WARNING: no policy specified for ldap/freeipaserver.lin.test.lan@LIN.TEST.LAN; defaulting to no policy 2020-06-17T10:06:21Z DEBUG Backing up system configuration file '/etc/dirsrv/ds.keytab' 2020-06-17T10:06:21Z DEBUG -> Not backing up - '/etc/dirsrv/ds.keytab' doesn't exist 2020-06-17T10:06:21Z DEBUG Starting external process 2020-06-17T10:06:21Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'ktadd -k /etc/dirsrv/ds.keytab ldap/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-x', 'ipa-setup-override-restrictions'] 2020-06-17T10:06:21Z DEBUG Process finished, return code=0 2020-06-17T10:06:21Z DEBUG stdout=Authenticating as principal root/admin@LIN.TEST.LAN with password. Entry for principal ldap/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/dirsrv/ds.keytab. Entry for principal ldap/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/dirsrv/ds.keytab. Entry for principal ldap/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type aes128-cts-hmac-sha256-128 added to keytab WRFILE:/etc/dirsrv/ds.keytab. Entry for principal ldap/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type aes256-cts-hmac-sha384-192 added to keytab WRFILE:/etc/dirsrv/ds.keytab. Entry for principal ldap/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/dirsrv/ds.keytab. Entry for principal ldap/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/dirsrv/ds.keytab. 2020-06-17T10:06:21Z DEBUG stderr= 2020-06-17T10:06:21Z DEBUG step duration: krb5kdc __create_ds_keytab 0.37 sec 2020-06-17T10:06:21Z DEBUG [6/10]: creating a keytab for the machine 2020-06-17T10:06:21Z DEBUG Starting external process 2020-06-17T10:06:21Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'addprinc -randkey host/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-x', 'ipa-setup-override-restrictions'] 2020-06-17T10:06:21Z DEBUG Process finished, return code=0 2020-06-17T10:06:21Z DEBUG stdout=Authenticating as principal root/admin@LIN.TEST.LAN with password. Principal "host/freeipaserver.lin.test.lan@LIN.TEST.LAN" created. 2020-06-17T10:06:21Z DEBUG stderr=WARNING: no policy specified for host/freeipaserver.lin.test.lan@LIN.TEST.LAN; defaulting to no policy 2020-06-17T10:06:21Z DEBUG Backing up system configuration file '/etc/krb5.keytab' 2020-06-17T10:06:21Z DEBUG -> Not backing up - '/etc/krb5.keytab' doesn't exist 2020-06-17T10:06:21Z DEBUG Starting external process 2020-06-17T10:06:21Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'ktadd -k /etc/krb5.keytab host/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-x', 'ipa-setup-override-restrictions'] 2020-06-17T10:06:21Z DEBUG Process finished, return code=0 2020-06-17T10:06:21Z DEBUG stdout=Authenticating as principal root/admin@LIN.TEST.LAN with password. Entry for principal host/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/krb5.keytab. Entry for principal host/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/krb5.keytab. Entry for principal host/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type aes128-cts-hmac-sha256-128 added to keytab WRFILE:/etc/krb5.keytab. Entry for principal host/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type aes256-cts-hmac-sha384-192 added to keytab WRFILE:/etc/krb5.keytab. Entry for principal host/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/krb5.keytab. Entry for principal host/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/krb5.keytab. 2020-06-17T10:06:21Z DEBUG stderr= 2020-06-17T10:06:21Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.aci 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.automember 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.automount 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-06-17T10:06:21Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.batch 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.ca 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.cert 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.config 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.dns 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.group 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-06-17T10:06:21Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.host 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.internal 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.join 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.location 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.migration 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.misc 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.otp 2020-06-17T10:06:21Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.permission 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.ping 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-06-17T10:06:21Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.role 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.schema 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.server 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.service 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.session 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-06-17T10:06:21Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.topology 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.trust 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.user 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.vault 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-06-17T10:06:21Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-06-17T10:06:21Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.install.plugins.dns 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2020-06-17T10:06:21Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2020-06-17T10:06:23Z DEBUG Created connection context.ldap2_139849977319152 2020-06-17T10:06:23Z DEBUG Destroyed connection context.ldap2_139849977319152 2020-06-17T10:06:23Z DEBUG Created connection context.ldap2_139849977319152 2020-06-17T10:06:23Z DEBUG Parsing update file '/usr/share/ipa/updates/20-ipaservers_hostgroup.update' 2020-06-17T10:06:23Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:06:23Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:06:23Z DEBUG Updating existing entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:06:23Z DEBUG --------------------------------------------- 2020-06-17T10:06:23Z DEBUG Initial value 2020-06-17T10:06:23Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:06:23Z DEBUG objectClass: 2020-06-17T10:06:23Z DEBUG top 2020-06-17T10:06:23Z DEBUG groupOfNames 2020-06-17T10:06:23Z DEBUG nestedGroup 2020-06-17T10:06:23Z DEBUG ipaobject 2020-06-17T10:06:23Z DEBUG ipahostgroup 2020-06-17T10:06:23Z DEBUG description: 2020-06-17T10:06:23Z DEBUG IPA server hosts 2020-06-17T10:06:23Z DEBUG cn: 2020-06-17T10:06:23Z DEBUG ipaservers 2020-06-17T10:06:23Z DEBUG ipaUniqueID: 2020-06-17T10:06:23Z DEBUG 3039958c-b082-11ea-921e-525400885899 2020-06-17T10:06:23Z DEBUG --------------------------------------------- 2020-06-17T10:06:23Z DEBUG Final value after applying updates 2020-06-17T10:06:23Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:06:23Z DEBUG objectClass: 2020-06-17T10:06:23Z DEBUG top 2020-06-17T10:06:23Z DEBUG groupOfNames 2020-06-17T10:06:23Z DEBUG nestedGroup 2020-06-17T10:06:23Z DEBUG ipaobject 2020-06-17T10:06:23Z DEBUG ipahostgroup 2020-06-17T10:06:23Z DEBUG description: 2020-06-17T10:06:23Z DEBUG IPA server hosts 2020-06-17T10:06:23Z DEBUG cn: 2020-06-17T10:06:23Z DEBUG ipaservers 2020-06-17T10:06:23Z DEBUG ipaUniqueID: 2020-06-17T10:06:23Z DEBUG 3039958c-b082-11ea-921e-525400885899 2020-06-17T10:06:23Z DEBUG [] 2020-06-17T10:06:23Z DEBUG Updated 0 2020-06-17T10:06:23Z DEBUG Done 2020-06-17T10:06:23Z DEBUG Updating existing entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:06:23Z DEBUG --------------------------------------------- 2020-06-17T10:06:23Z DEBUG Initial value 2020-06-17T10:06:23Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:06:23Z DEBUG objectClass: 2020-06-17T10:06:23Z DEBUG top 2020-06-17T10:06:23Z DEBUG groupOfNames 2020-06-17T10:06:23Z DEBUG nestedGroup 2020-06-17T10:06:23Z DEBUG ipaobject 2020-06-17T10:06:23Z DEBUG ipahostgroup 2020-06-17T10:06:23Z DEBUG description: 2020-06-17T10:06:23Z DEBUG IPA server hosts 2020-06-17T10:06:23Z DEBUG cn: 2020-06-17T10:06:23Z DEBUG ipaservers 2020-06-17T10:06:23Z DEBUG ipaUniqueID: 2020-06-17T10:06:23Z DEBUG 3039958c-b082-11ea-921e-525400885899 2020-06-17T10:06:23Z DEBUG add: 'fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan' to member, current value [] 2020-06-17T10:06:23Z DEBUG add: updated value ['fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:06:23Z DEBUG --------------------------------------------- 2020-06-17T10:06:23Z DEBUG Final value after applying updates 2020-06-17T10:06:23Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:06:23Z DEBUG objectClass: 2020-06-17T10:06:23Z DEBUG top 2020-06-17T10:06:23Z DEBUG groupOfNames 2020-06-17T10:06:23Z DEBUG nestedGroup 2020-06-17T10:06:23Z DEBUG ipaobject 2020-06-17T10:06:23Z DEBUG ipahostgroup 2020-06-17T10:06:23Z DEBUG description: 2020-06-17T10:06:23Z DEBUG IPA server hosts 2020-06-17T10:06:23Z DEBUG cn: 2020-06-17T10:06:23Z DEBUG ipaservers 2020-06-17T10:06:23Z DEBUG ipaUniqueID: 2020-06-17T10:06:23Z DEBUG 3039958c-b082-11ea-921e-525400885899 2020-06-17T10:06:23Z DEBUG member: 2020-06-17T10:06:23Z DEBUG fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:06:23Z DEBUG [(2, 'member', ['fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:06:23Z DEBUG Updated 1 2020-06-17T10:06:23Z DEBUG Done 2020-06-17T10:06:23Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-ipaservers_hostgroup.update 0.165 sec 2020-06-17T10:06:23Z DEBUG Destroyed connection context.ldap2_139849977319152 2020-06-17T10:06:23Z DEBUG step duration: krb5kdc __create_host_keytab 1.74 sec 2020-06-17T10:06:23Z DEBUG [7/10]: adding the password extension to the directory 2020-06-17T10:06:23Z DEBUG Starting external process 2020-06-17T10:06:23Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp8ao2pgp7', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:23Z DEBUG Process finished, return code=0 2020-06-17T10:06:23Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa_pwd_extop add nsslapd-pluginpath: libipa_pwd_extop add nsslapd-plugininitfunc: ipapwd_init add nsslapd-plugintype: extendedop add nsslapd-pluginbetxn: on add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_pwd_extop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: RedHat add nsslapd-plugindescription: Support saving passwords in multiple formats for different consumers (krb5, samba, freeradius, etc.) add nsslapd-plugin-depends-on-type: database add nsslapd-realmTree: dc=lin,dc=test,dc=lan adding new entry "cn=ipa_pwd_extop,cn=plugins,cn=config" modify complete 2020-06-17T10:06:23Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:23Z DEBUG step duration: krb5kdc __add_pwd_extop_module 0.02 sec 2020-06-17T10:06:23Z DEBUG [8/10]: creating anonymous principal 2020-06-17T10:06:23Z DEBUG Starting external process 2020-06-17T10:06:23Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'addprinc -randkey WELLKNOWN/ANONYMOUS@LIN.TEST.LAN', '-x', 'ipa-setup-override-restrictions'] 2020-06-17T10:06:23Z DEBUG Process finished, return code=0 2020-06-17T10:06:23Z DEBUG stdout=Authenticating as principal root/admin@LIN.TEST.LAN with password. Principal "WELLKNOWN/ANONYMOUS@LIN.TEST.LAN" created. 2020-06-17T10:06:23Z DEBUG stderr=WARNING: no policy specified for WELLKNOWN/ANONYMOUS@LIN.TEST.LAN; defaulting to no policy 2020-06-17T10:06:23Z DEBUG Starting external process 2020-06-17T10:06:23Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpyx971lxk', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:06:23Z DEBUG Process finished, return code=0 2020-06-17T10:06:23Z DEBUG stdout=add objectclass: ipaAllowedOperations add aci: (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) add ipaAllowedToPerform;read_keys: cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan modifying entry "krbPrincipalName=WELLKNOWN/ANONYMOUS@LIN.TEST.LAN,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan" modify complete 2020-06-17T10:06:23Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:06:23Z DEBUG step duration: krb5kdc add_anonymous_principal 0.16 sec 2020-06-17T10:06:23Z DEBUG [9/10]: starting the KDC 2020-06-17T10:06:23Z DEBUG Starting external process 2020-06-17T10:06:23Z DEBUG args=['/bin/systemctl', 'start', 'krb5kdc.service'] 2020-06-17T10:06:23Z DEBUG Process finished, return code=0 2020-06-17T10:06:23Z DEBUG stdout= 2020-06-17T10:06:23Z DEBUG stderr= 2020-06-17T10:06:23Z DEBUG Starting external process 2020-06-17T10:06:23Z DEBUG args=['/bin/systemctl', 'is-active', 'krb5kdc.service'] 2020-06-17T10:06:23Z DEBUG Process finished, return code=0 2020-06-17T10:06:23Z DEBUG stdout=active 2020-06-17T10:06:23Z DEBUG stderr= 2020-06-17T10:06:23Z DEBUG Start of krb5kdc.service complete 2020-06-17T10:06:23Z DEBUG step duration: krb5kdc __start_instance 0.07 sec 2020-06-17T10:06:23Z DEBUG [10/10]: configuring KDC to start on boot 2020-06-17T10:06:23Z DEBUG Starting external process 2020-06-17T10:06:23Z DEBUG args=['/bin/systemctl', 'is-enabled', 'krb5kdc.service'] 2020-06-17T10:06:23Z DEBUG Process finished, return code=1 2020-06-17T10:06:23Z DEBUG stdout=disabled 2020-06-17T10:06:23Z DEBUG stderr= 2020-06-17T10:06:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:23Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:23Z DEBUG Starting external process 2020-06-17T10:06:23Z DEBUG args=['/bin/systemctl', 'disable', 'krb5kdc.service'] 2020-06-17T10:06:23Z DEBUG Process finished, return code=0 2020-06-17T10:06:23Z DEBUG stdout= 2020-06-17T10:06:23Z DEBUG stderr= 2020-06-17T10:06:23Z DEBUG step duration: krb5kdc __enable 0.18 sec 2020-06-17T10:06:23Z DEBUG Done configuring Kerberos KDC (krb5kdc). 2020-06-17T10:06:23Z DEBUG service duration: krb5kdc 2.84 sec 2020-06-17T10:06:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:23Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:06:23Z DEBUG Configuring kadmin 2020-06-17T10:06:23Z DEBUG [1/2]: starting kadmin 2020-06-17T10:06:23Z DEBUG Starting external process 2020-06-17T10:06:23Z DEBUG args=['/bin/systemctl', 'is-active', 'kadmin.service'] 2020-06-17T10:06:23Z DEBUG Process finished, return code=3 2020-06-17T10:06:23Z DEBUG stdout=inactive 2020-06-17T10:06:23Z DEBUG stderr= 2020-06-17T10:06:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:23Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:23Z DEBUG Starting external process 2020-06-17T10:06:23Z DEBUG args=['/bin/systemctl', 'restart', 'kadmin.service'] 2020-06-17T10:06:23Z DEBUG Process finished, return code=0 2020-06-17T10:06:23Z DEBUG stdout= 2020-06-17T10:06:23Z DEBUG stderr= 2020-06-17T10:06:23Z DEBUG Starting external process 2020-06-17T10:06:23Z DEBUG args=['/bin/systemctl', 'is-active', 'kadmin.service'] 2020-06-17T10:06:23Z DEBUG Process finished, return code=0 2020-06-17T10:06:23Z DEBUG stdout=active 2020-06-17T10:06:23Z DEBUG stderr= 2020-06-17T10:06:23Z DEBUG Restart of kadmin.service complete 2020-06-17T10:06:23Z DEBUG step duration: kadmin __start 0.20 sec 2020-06-17T10:06:23Z DEBUG [2/2]: configuring kadmin to start on boot 2020-06-17T10:06:23Z DEBUG Starting external process 2020-06-17T10:06:23Z DEBUG args=['/bin/systemctl', 'is-enabled', 'kadmin.service'] 2020-06-17T10:06:23Z DEBUG Process finished, return code=1 2020-06-17T10:06:23Z DEBUG stdout=disabled 2020-06-17T10:06:23Z DEBUG stderr= 2020-06-17T10:06:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:23Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:23Z DEBUG Starting external process 2020-06-17T10:06:23Z DEBUG args=['/bin/systemctl', 'disable', 'kadmin.service'] 2020-06-17T10:06:24Z DEBUG Process finished, return code=0 2020-06-17T10:06:24Z DEBUG stdout= 2020-06-17T10:06:24Z DEBUG stderr= 2020-06-17T10:06:24Z DEBUG step duration: kadmin __enable 0.20 sec 2020-06-17T10:06:24Z DEBUG Done configuring kadmin. 2020-06-17T10:06:24Z DEBUG service duration: kadmin 0.40 sec 2020-06-17T10:06:24Z DEBUG Custodia client for '' with promotion no. 2020-06-17T10:06:24Z DEBUG Custodia uses LDAPI. 2020-06-17T10:06:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:24Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:06:24Z DEBUG Configuring ipa-custodia 2020-06-17T10:06:24Z DEBUG [1/5]: Making sure custodia container exists 2020-06-17T10:06:24Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.aci 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.automember 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.automount 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-06-17T10:06:24Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.batch 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.ca 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.cert 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.config 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.dns 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.group 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-06-17T10:06:24Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.host 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.internal 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.join 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.location 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.migration 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.misc 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.otp 2020-06-17T10:06:24Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.permission 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.ping 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-06-17T10:06:24Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.role 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.schema 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.server 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.service 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.session 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-06-17T10:06:24Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.topology 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.trust 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.user 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.vault 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-06-17T10:06:24Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-06-17T10:06:24Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.install.plugins.dns 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2020-06-17T10:06:24Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2020-06-17T10:06:25Z DEBUG Created connection context.ldap2_139849943148248 2020-06-17T10:06:25Z DEBUG Destroyed connection context.ldap2_139849943148248 2020-06-17T10:06:25Z DEBUG Created connection context.ldap2_139849943148248 2020-06-17T10:06:25Z DEBUG Parsing update file '/usr/share/ipa/updates/73-custodia.update' 2020-06-17T10:06:25Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:06:25Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:06:25Z DEBUG Updating existing entry: cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:06:25Z DEBUG --------------------------------------------- 2020-06-17T10:06:25Z DEBUG Initial value 2020-06-17T10:06:25Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:06:25Z DEBUG objectClass: 2020-06-17T10:06:25Z DEBUG nsContainer 2020-06-17T10:06:25Z DEBUG top 2020-06-17T10:06:25Z DEBUG cn: 2020-06-17T10:06:25Z DEBUG custodia 2020-06-17T10:06:25Z DEBUG --------------------------------------------- 2020-06-17T10:06:25Z DEBUG Final value after applying updates 2020-06-17T10:06:25Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:06:25Z DEBUG objectClass: 2020-06-17T10:06:25Z DEBUG nsContainer 2020-06-17T10:06:25Z DEBUG top 2020-06-17T10:06:25Z DEBUG cn: 2020-06-17T10:06:25Z DEBUG custodia 2020-06-17T10:06:25Z DEBUG [] 2020-06-17T10:06:25Z DEBUG Updated 0 2020-06-17T10:06:25Z DEBUG Done 2020-06-17T10:06:25Z DEBUG Updating existing entry: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:06:25Z DEBUG --------------------------------------------- 2020-06-17T10:06:25Z DEBUG Initial value 2020-06-17T10:06:25Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:06:25Z DEBUG objectClass: 2020-06-17T10:06:25Z DEBUG nsContainer 2020-06-17T10:06:25Z DEBUG top 2020-06-17T10:06:25Z DEBUG cn: 2020-06-17T10:06:25Z DEBUG dogtag 2020-06-17T10:06:25Z DEBUG --------------------------------------------- 2020-06-17T10:06:25Z DEBUG Final value after applying updates 2020-06-17T10:06:25Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:06:25Z DEBUG objectClass: 2020-06-17T10:06:25Z DEBUG nsContainer 2020-06-17T10:06:25Z DEBUG top 2020-06-17T10:06:25Z DEBUG cn: 2020-06-17T10:06:25Z DEBUG dogtag 2020-06-17T10:06:25Z DEBUG [] 2020-06-17T10:06:25Z DEBUG Updated 0 2020-06-17T10:06:25Z DEBUG Done 2020-06-17T10:06:25Z DEBUG LDAP update duration: /usr/share/ipa/updates/73-custodia.update 0.152 sec 2020-06-17T10:06:25Z DEBUG Destroyed connection context.ldap2_139849943148248 2020-06-17T10:06:25Z DEBUG step duration: ipa-custodia __create_container 1.55 sec 2020-06-17T10:06:25Z DEBUG [2/5]: Generating ipa-custodia config file 2020-06-17T10:06:25Z DEBUG step duration: ipa-custodia __config_file 0.02 sec 2020-06-17T10:06:25Z DEBUG [3/5]: Generating ipa-custodia keys 2020-06-17T10:06:25Z DEBUG step duration: ipa-custodia __gen_keys 0.15 sec 2020-06-17T10:06:25Z DEBUG [4/5]: starting ipa-custodia 2020-06-17T10:06:25Z DEBUG Starting external process 2020-06-17T10:06:25Z DEBUG args=['/bin/systemctl', 'is-active', 'ipa-custodia.service'] 2020-06-17T10:06:25Z DEBUG Process finished, return code=3 2020-06-17T10:06:25Z DEBUG stdout=inactive 2020-06-17T10:06:25Z DEBUG stderr= 2020-06-17T10:06:25Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:25Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:25Z DEBUG Starting external process 2020-06-17T10:06:25Z DEBUG args=['/bin/systemctl', 'restart', 'ipa-custodia.service'] 2020-06-17T10:06:26Z DEBUG Process finished, return code=0 2020-06-17T10:06:26Z DEBUG stdout= 2020-06-17T10:06:26Z DEBUG stderr= 2020-06-17T10:06:26Z DEBUG Starting external process 2020-06-17T10:06:26Z DEBUG args=['/bin/systemctl', 'is-active', 'ipa-custodia.service'] 2020-06-17T10:06:26Z DEBUG Process finished, return code=0 2020-06-17T10:06:26Z DEBUG stdout=active 2020-06-17T10:06:26Z DEBUG stderr= 2020-06-17T10:06:26Z DEBUG Restart of ipa-custodia.service complete 2020-06-17T10:06:26Z DEBUG step duration: ipa-custodia __start 0.55 sec 2020-06-17T10:06:26Z DEBUG [5/5]: configuring ipa-custodia to start on boot 2020-06-17T10:06:26Z DEBUG Starting external process 2020-06-17T10:06:26Z DEBUG args=['/bin/systemctl', 'is-enabled', 'ipa-custodia.service'] 2020-06-17T10:06:26Z DEBUG Process finished, return code=1 2020-06-17T10:06:26Z DEBUG stdout=disabled 2020-06-17T10:06:26Z DEBUG stderr= 2020-06-17T10:06:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:26Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:26Z DEBUG Starting external process 2020-06-17T10:06:26Z DEBUG args=['/bin/systemctl', 'disable', 'ipa-custodia.service'] 2020-06-17T10:06:26Z DEBUG Process finished, return code=0 2020-06-17T10:06:26Z DEBUG stdout= 2020-06-17T10:06:26Z DEBUG stderr= 2020-06-17T10:06:26Z DEBUG step duration: ipa-custodia __enable 0.20 sec 2020-06-17T10:06:26Z DEBUG Done configuring ipa-custodia. 2020-06-17T10:06:26Z DEBUG service duration: ipa-custodia 2.47 sec 2020-06-17T10:06:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:06:26Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:06:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:06:26Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:06:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:26Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:06:26Z DEBUG Configuring certificate server (pki-tomcatd). Estimated time: 3 minutes 2020-06-17T10:06:26Z DEBUG [1/29]: configuring certificate server instance 2020-06-17T10:06:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:26Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:26Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:26Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:06:26Z DEBUG Contents of pkispawn configuration file (/tmp/tmp40_v032q): [CA] pki_admin_cert_file = /root/.dogtag/pki-tomcat/ca_admin.cert pki_admin_cert_request_type = pkcs10 pki_admin_dualkey = False pki_admin_email = root@localhost pki_admin_name = admin pki_admin_nickname = ipa-ca-agent pki_admin_password = XXXXXXXX pki_admin_subject_dn = cn=ipa-ca-agent,O=LIN.TEST.LAN pki_admin_uid = admin pki_audit_group = pkiaudit pki_audit_signing_key_algorithm = SHA256withRSA pki_audit_signing_key_size = 2048 pki_audit_signing_key_type = rsa pki_audit_signing_nickname = auditSigningCert cert-pki-ca pki_audit_signing_signing_algorithm = SHA256withRSA pki_audit_signing_subject_dn = cn=CA Audit,O=LIN.TEST.LAN pki_audit_signing_token = internal pki_backup_keys = True pki_backup_password = XXXXXXXX pki_ca_hostname = freeipaserver.lin.test.lan pki_ca_port = 443 pki_ca_signing_cert_path = /etc/pki/pki-tomcat/external_ca.cert pki_ca_signing_csr_path = /root/ipa.csr pki_ca_signing_key_algorithm = SHA256withRSA pki_ca_signing_key_size = 3072 pki_ca_signing_key_type = rsa pki_ca_signing_nickname = caSigningCert cert-pki-ca pki_ca_signing_record_create = True pki_ca_signing_serial_number = 1 pki_ca_signing_signing_algorithm = SHA256withRSA pki_ca_signing_subject_dn = CN=Certificate Authority,O=LIN.TEST.LAN pki_ca_signing_token = internal pki_ca_starting_crl_number = 0 pki_cert_chain_nickname = caSigningCert External CA pki_cert_chain_path = /etc/pki/pki-tomcat/external_ca_chain.cert pki_client_admin_cert_p12 = /root/ca-agent.p12 pki_client_database_password = pki_client_database_purge = True pki_client_dir = /root/.dogtag/pki-tomcat pki_client_pkcs12_password = XXXXXXXX pki_configuration_path = /etc/pki pki_default_ocsp_uri = http://ipa-ca.lin.test.lan/ca/ocsp pki_dns_domainname = lin.test.lan pki_ds_base_dn = o=ipaca pki_ds_bind_dn = cn=Directory Manager pki_ds_database = ipaca pki_ds_hostname = freeipaserver.lin.test.lan pki_ds_ldap_port = 389 pki_ds_ldaps_port = 636 pki_ds_password = XXXXXXXX pki_ds_remove_data = True pki_ds_secure_connection = False pki_ds_secure_connection_ca_nickname = Directory Server CA certificate pki_ds_secure_connection_ca_pem_file = /etc/ipa/ca.crt pki_enable_proxy = True pki_existing = False pki_external = False pki_external_pkcs12_password = pki_external_pkcs12_path = pki_external_step_two = False pki_group = pkiuser pki_hostname = freeipaserver.lin.test.lan pki_hsm_enable = False pki_hsm_libfile = pki_hsm_modulename = pki_import_admin_cert = False pki_instance_configuration_path = /etc/pki/pki-tomcat pki_instance_name = pki-tomcat pki_issuing_ca = https://freeipaserver.lin.test.lan:443 pki_issuing_ca_hostname = freeipaserver.lin.test.lan pki_issuing_ca_https_port = 443 pki_issuing_ca_uri = https://freeipaserver.lin.test.lan:443 pki_master_crl_enable = True pki_ocsp_signing_key_algorithm = SHA256withRSA pki_ocsp_signing_key_size = 2048 pki_ocsp_signing_key_type = rsa pki_ocsp_signing_nickname = ocspSigningCert cert-pki-ca pki_ocsp_signing_signing_algorithm = SHA256withRSA pki_ocsp_signing_subject_dn = cn=OCSP Subsystem,O=LIN.TEST.LAN pki_ocsp_signing_token = internal pki_pkcs12_password = pki_pkcs12_path = pki_profiles_in_ldap = True pki_random_serial_numbers_enable = False pki_replica_number_range_end = 100 pki_replica_number_range_start = 1 pki_replication_password = pki_request_number_range_end = 10000000 pki_request_number_range_start = 1 pki_restart_configured_instance = False pki_san_for_server_cert = pki_san_inject = False pki_security_domain_hostname = freeipaserver.lin.test.lan pki_security_domain_https_port = 443 pki_security_domain_name = IPA pki_security_domain_password = XXXXXXXX pki_security_domain_user = admin pki_self_signed_token = internal pki_serial_number_range_end = 10000000 pki_serial_number_range_start = 1 pki_server_database_password = XXXXXXXX pki_share_db = False pki_skip_configuration = False pki_skip_ds_verify = False pki_skip_installation = False pki_skip_sd_verify = False pki_ssl_server_token = internal pki_sslserver_key_algorithm = SHA256withRSA pki_sslserver_key_size = 2048 pki_sslserver_key_type = rsa pki_sslserver_nickname = Server-Cert cert-pki-ca pki_sslserver_subject_dn = cn=freeipaserver.lin.test.lan,O=LIN.TEST.LAN pki_sslserver_token = internal pki_status_request_timeout = 15 pki_subordinate = False pki_subordinate_create_new_security_domain = False pki_subsystem = CA pki_subsystem_key_algorithm = SHA256withRSA pki_subsystem_key_size = 2048 pki_subsystem_key_type = rsa pki_subsystem_nickname = subsystemCert cert-pki-ca pki_subsystem_subject_dn = cn=CA Subsystem,O=LIN.TEST.LAN pki_subsystem_token = internal pki_subsystem_type = ca pki_theme_enable = True pki_theme_server_dir = /usr/share/pki/common-ui pki_token_name = internal pki_user = pkiuser 2020-06-17T10:06:26Z DEBUG Starting external process 2020-06-17T10:06:26Z DEBUG args=['/usr/sbin/pkispawn', '-s', 'CA', '-f', '/tmp/tmp40_v032q'] 2020-06-17T10:07:44Z DEBUG Process finished, return code=0 2020-06-17T10:07:44Z DEBUG stdout=--------------- Export complete --------------- Installation log: /var/log/pki/pki-ca-spawn.20200617060627.log Loading deployment configuration from /tmp/tmp40_v032q. WARNING: The 'pki_ssl_server_token' in [CA] has been deprecated. Use 'pki_sslserver_token' instead. Installing CA into /var/lib/pki/pki-tomcat. ========================================================================== INSTALLATION SUMMARY ========================================================================== Administrator's username: admin Administrator's PKCS #12 file: /root/ca-agent.p12 To check the status of the subsystem: systemctl status pki-tomcatd@pki-tomcat.service To restart the subsystem: systemctl restart pki-tomcatd@pki-tomcat.service The URL for the subsystem is: https://freeipaserver.lin.test.lan:8443/ca PKI instances will be enabled upon system boot ========================================================================== 2020-06-17T10:07:44Z DEBUG stderr=Notice: Trust flag u is set automatically if the private key is present. 2020-06-17T10:07:44Z DEBUG completed creating ca instance 2020-06-17T10:07:44Z DEBUG step duration: pki-tomcatd __spawn_instance 77.70 sec 2020-06-17T10:07:44Z DEBUG [2/29]: Add ipa-pki-wait-running 2020-06-17T10:07:44Z DEBUG Starting external process 2020-06-17T10:07:44Z DEBUG args=['/bin/systemctl', '--system', 'daemon-reload'] 2020-06-17T10:07:44Z DEBUG Process finished, return code=0 2020-06-17T10:07:44Z DEBUG stdout= 2020-06-17T10:07:44Z DEBUG stderr= 2020-06-17T10:07:44Z DEBUG step duration: pki-tomcatd add_ipa_wait 0.17 sec 2020-06-17T10:07:44Z DEBUG [3/29]: reindex attributes 2020-06-17T10:07:44Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:07:44Z DEBUG Creating ipaca reindex task cn=indextask_ipaca_1592388464,cn=index,cn=tasks,cn=config 2020-06-17T10:07:44Z DEBUG Waiting for task... 2020-06-17T10:07:45Z DEBUG Task cn=indextask_ipaca_1592388464,cn=index,cn=tasks,cn=config has finished with exit code 0 2020-06-17T10:07:45Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:07:45Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:07:45Z DEBUG step duration: pki-tomcatd reindex_task 1.02 sec 2020-06-17T10:07:45Z DEBUG [4/29]: exporting Dogtag certificate store pin 2020-06-17T10:07:45Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:07:45Z DEBUG step duration: pki-tomcatd create_certstore_passwdfile 0.00 sec 2020-06-17T10:07:45Z DEBUG [5/29]: stopping certificate server instance to update CS.cfg 2020-06-17T10:07:45Z DEBUG Starting external process 2020-06-17T10:07:45Z DEBUG args=['/bin/systemctl', 'stop', 'pki-tomcatd@pki-tomcat.service'] 2020-06-17T10:07:46Z DEBUG Process finished, return code=0 2020-06-17T10:07:46Z DEBUG stdout= 2020-06-17T10:07:46Z DEBUG stderr= 2020-06-17T10:07:46Z DEBUG Stop of pki-tomcatd@pki-tomcat.service complete 2020-06-17T10:07:46Z DEBUG step duration: pki-tomcatd stop_instance 0.87 sec 2020-06-17T10:07:46Z DEBUG [6/29]: backing up CS.cfg 2020-06-17T10:07:46Z DEBUG Starting external process 2020-06-17T10:07:46Z DEBUG args=['/bin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2020-06-17T10:07:46Z DEBUG Process finished, return code=3 2020-06-17T10:07:46Z DEBUG stdout=inactive 2020-06-17T10:07:46Z DEBUG stderr= 2020-06-17T10:07:46Z DEBUG step duration: pki-tomcatd safe_backup_config 0.03 sec 2020-06-17T10:07:46Z DEBUG [7/29]: disabling nonces 2020-06-17T10:07:46Z DEBUG step duration: pki-tomcatd __disable_nonce 0.00 sec 2020-06-17T10:07:46Z DEBUG [8/29]: set up CRL publishing 2020-06-17T10:07:46Z DEBUG Starting external process 2020-06-17T10:07:46Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T10:07:46Z DEBUG Process finished, return code=0 2020-06-17T10:07:46Z DEBUG stdout= 2020-06-17T10:07:46Z DEBUG stderr= 2020-06-17T10:07:46Z DEBUG Starting external process 2020-06-17T10:07:46Z DEBUG args=['/sbin/restorecon', '/var/lib/ipa/pki-ca/publish'] 2020-06-17T10:07:46Z DEBUG Process finished, return code=0 2020-06-17T10:07:46Z DEBUG stdout= 2020-06-17T10:07:46Z DEBUG stderr= 2020-06-17T10:07:46Z DEBUG step duration: pki-tomcatd __enable_crl_publish 0.06 sec 2020-06-17T10:07:46Z DEBUG [9/29]: enable PKIX certificate path discovery and validation 2020-06-17T10:07:46Z DEBUG step duration: pki-tomcatd enable_pkix 0.00 sec 2020-06-17T10:07:46Z DEBUG [10/29]: starting certificate server instance 2020-06-17T10:07:46Z DEBUG Starting external process 2020-06-17T10:07:46Z DEBUG args=['/bin/systemctl', 'start', 'pki-tomcatd@pki-tomcat.service'] 2020-06-17T10:08:01Z DEBUG Process finished, return code=0 2020-06-17T10:08:01Z DEBUG stdout= 2020-06-17T10:08:01Z DEBUG stderr= 2020-06-17T10:08:01Z DEBUG Starting external process 2020-06-17T10:08:01Z DEBUG args=['/bin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2020-06-17T10:08:01Z DEBUG Process finished, return code=0 2020-06-17T10:08:01Z DEBUG stdout=active 2020-06-17T10:08:01Z DEBUG stderr= 2020-06-17T10:08:01Z DEBUG wait_for_open_ports: localhost [8080, 8443] timeout 120 2020-06-17T10:08:01Z DEBUG waiting for port: 8080 2020-06-17T10:08:01Z DEBUG SUCCESS: port: 8080 2020-06-17T10:08:01Z DEBUG waiting for port: 8443 2020-06-17T10:08:01Z DEBUG SUCCESS: port: 8443 2020-06-17T10:08:01Z DEBUG Start of pki-tomcatd@pki-tomcat.service complete 2020-06-17T10:08:01Z DEBUG step duration: pki-tomcatd start_instance 15.21 sec 2020-06-17T10:08:01Z DEBUG [11/29]: configure certmonger for renewals 2020-06-17T10:08:01Z DEBUG Starting external process 2020-06-17T10:08:01Z DEBUG args=['/bin/systemctl', 'enable', 'certmonger.service'] 2020-06-17T10:08:01Z DEBUG Process finished, return code=0 2020-06-17T10:08:01Z DEBUG stdout= 2020-06-17T10:08:01Z DEBUG stderr=Created symlink /etc/systemd/system/multi-user.target.wants/certmonger.service → /usr/lib/systemd/system/certmonger.service. 2020-06-17T10:08:01Z DEBUG Starting external process 2020-06-17T10:08:01Z DEBUG args=['/bin/systemctl', 'is-active', 'dbus.service'] 2020-06-17T10:08:01Z DEBUG Process finished, return code=0 2020-06-17T10:08:01Z DEBUG stdout=active 2020-06-17T10:08:01Z DEBUG stderr= 2020-06-17T10:08:01Z DEBUG Starting external process 2020-06-17T10:08:01Z DEBUG args=['/bin/systemctl', 'start', 'certmonger.service'] 2020-06-17T10:08:01Z DEBUG Process finished, return code=0 2020-06-17T10:08:01Z DEBUG stdout= 2020-06-17T10:08:01Z DEBUG stderr= 2020-06-17T10:08:01Z DEBUG Starting external process 2020-06-17T10:08:01Z DEBUG args=['/bin/systemctl', 'is-active', 'certmonger.service'] 2020-06-17T10:08:01Z DEBUG Process finished, return code=0 2020-06-17T10:08:01Z DEBUG stdout=active 2020-06-17T10:08:01Z DEBUG stderr= 2020-06-17T10:08:01Z DEBUG Start of certmonger.service complete 2020-06-17T10:08:02Z DEBUG step duration: pki-tomcatd configure_certmonger_renewal 0.95 sec 2020-06-17T10:08:02Z DEBUG [12/29]: requesting RA certificate from CA 2020-06-17T10:08:02Z DEBUG Starting external process 2020-06-17T10:08:02Z DEBUG args=['/usr/bin/openssl', 'pkcs7', '-inform', 'DER', '-print_certs', '-out', '/var/lib/ipa/tmpw6o3730r'] 2020-06-17T10:08:02Z DEBUG Process finished, return code=0 2020-06-17T10:08:02Z DEBUG stdout= 2020-06-17T10:08:02Z DEBUG stderr= 2020-06-17T10:08:02Z DEBUG Starting external process 2020-06-17T10:08:02Z DEBUG args=['/usr/bin/openssl', 'pkcs12', '-nokeys', '-clcerts', '-in', '/root/ca-agent.p12', '-out', '/var/lib/ipa/tmpuljw3zt1', '-passin', 'file:/tmp/tmpwnmoc1xi'] 2020-06-17T10:08:08Z DEBUG Process finished, return code=0 2020-06-17T10:08:08Z DEBUG stdout= 2020-06-17T10:08:08Z DEBUG stderr= 2020-06-17T10:08:08Z DEBUG Starting external process 2020-06-17T10:08:08Z DEBUG args=['/usr/bin/openssl', 'pkcs12', '-nocerts', '-in', '/root/ca-agent.p12', '-out', '/var/lib/ipa/tmp1dse_2uu', '-passin', 'file:/tmp/tmpdt6ypx6j', '-nodes'] 2020-06-17T10:08:14Z DEBUG Process finished, return code=0 2020-06-17T10:08:14Z DEBUG stdout= 2020-06-17T10:08:14Z DEBUG stderr= 2020-06-17T10:08:14Z DEBUG certmonger request is in state dbus.String('NEWLY_ADDED_READING_KEYINFO', variant_level=1) 2020-06-17T10:08:19Z DEBUG certmonger request is in state dbus.String('POST_SAVED_CERT', variant_level=1) 2020-06-17T10:08:24Z DEBUG certmonger request is in state dbus.String('MONITORING', variant_level=1) 2020-06-17T10:08:24Z DEBUG Cert request 20200617100814 was successful 2020-06-17T10:08:24Z DEBUG Starting external process 2020-06-17T10:08:24Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T10:08:24Z DEBUG Process finished, return code=0 2020-06-17T10:08:24Z DEBUG stdout= 2020-06-17T10:08:24Z DEBUG stderr= 2020-06-17T10:08:24Z DEBUG Starting external process 2020-06-17T10:08:24Z DEBUG args=['/sbin/restorecon', '/var/lib/ipa/ra-agent.pem'] 2020-06-17T10:08:24Z DEBUG Process finished, return code=0 2020-06-17T10:08:24Z DEBUG stdout= 2020-06-17T10:08:24Z DEBUG stderr= 2020-06-17T10:08:24Z DEBUG Starting external process 2020-06-17T10:08:24Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T10:08:24Z DEBUG Process finished, return code=0 2020-06-17T10:08:24Z DEBUG stdout= 2020-06-17T10:08:24Z DEBUG stderr= 2020-06-17T10:08:24Z DEBUG Starting external process 2020-06-17T10:08:24Z DEBUG args=['/sbin/restorecon', '/var/lib/ipa/ra-agent.key'] 2020-06-17T10:08:24Z DEBUG Process finished, return code=0 2020-06-17T10:08:24Z DEBUG stdout= 2020-06-17T10:08:24Z DEBUG stderr= 2020-06-17T10:08:24Z DEBUG step duration: pki-tomcatd __request_ra_certificate 22.18 sec 2020-06-17T10:08:24Z DEBUG [13/29]: setting audit signing renewal to 2 years 2020-06-17T10:08:24Z DEBUG caSignedLogCert.cfg profile validity range is 720 2020-06-17T10:08:24Z DEBUG step duration: pki-tomcatd set_audit_renewal 0.00 sec 2020-06-17T10:08:24Z DEBUG [14/29]: restarting certificate server 2020-06-17T10:08:24Z DEBUG Starting external process 2020-06-17T10:08:24Z DEBUG args=['/bin/systemctl', 'restart', 'pki-tomcatd@pki-tomcat.service'] 2020-06-17T10:08:45Z DEBUG Process finished, return code=0 2020-06-17T10:08:45Z DEBUG stdout= 2020-06-17T10:08:45Z DEBUG stderr= 2020-06-17T10:08:45Z DEBUG Starting external process 2020-06-17T10:08:45Z DEBUG args=['/bin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2020-06-17T10:08:45Z DEBUG Process finished, return code=0 2020-06-17T10:08:45Z DEBUG stdout=active 2020-06-17T10:08:45Z DEBUG stderr= 2020-06-17T10:08:45Z DEBUG wait_for_open_ports: localhost [8080, 8443] timeout 120 2020-06-17T10:08:45Z DEBUG waiting for port: 8080 2020-06-17T10:08:45Z DEBUG SUCCESS: port: 8080 2020-06-17T10:08:45Z DEBUG waiting for port: 8443 2020-06-17T10:08:45Z DEBUG SUCCESS: port: 8443 2020-06-17T10:08:45Z DEBUG Restart of pki-tomcatd@pki-tomcat.service complete 2020-06-17T10:08:45Z DEBUG step duration: pki-tomcatd restart_instance 21.05 sec 2020-06-17T10:08:45Z DEBUG [15/29]: publishing the CA certificate 2020-06-17T10:08:45Z DEBUG step duration: pki-tomcatd __export_ca_chain 0.05 sec 2020-06-17T10:08:45Z DEBUG [16/29]: adding RA agent as a trusted user 2020-06-17T10:08:45Z DEBUG Created connection context.ldap2_139849941604448 2020-06-17T10:08:45Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:08:45Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:08:46Z DEBUG add_entry_to_group: dn=uid=ipara,ou=People,o=ipaca group_dn=cn=Certificate Manager Agents,ou=groups,o=ipaca member_attr=uniqueMember 2020-06-17T10:08:46Z DEBUG add_entry_to_group: dn=uid=ipara,ou=People,o=ipaca group_dn=cn=Registration Manager Agents,ou=groups,o=ipaca member_attr=uniqueMember 2020-06-17T10:08:46Z DEBUG Destroyed connection context.ldap2_139849941604448 2020-06-17T10:08:46Z DEBUG step duration: pki-tomcatd __create_ca_agent 0.28 sec 2020-06-17T10:08:46Z DEBUG [17/29]: authorizing RA to modify profiles 2020-06-17T10:08:46Z DEBUG step duration: pki-tomcatd configure_profiles_acl 0.01 sec 2020-06-17T10:08:46Z DEBUG [18/29]: authorizing RA to manage lightweight CAs 2020-06-17T10:08:46Z DEBUG step duration: pki-tomcatd configure_lightweight_ca_acls 0.01 sec 2020-06-17T10:08:46Z DEBUG [19/29]: Ensure lightweight CAs container exists 2020-06-17T10:08:46Z DEBUG Created connection context.ldap2_139849941605120 2020-06-17T10:08:46Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:08:46Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:08:46Z DEBUG Destroyed connection context.ldap2_139849941605120 2020-06-17T10:08:46Z DEBUG step duration: pki-tomcatd ensure_lightweight_cas_container 0.16 sec 2020-06-17T10:08:46Z DEBUG [20/29]: configure certificate renewals 2020-06-17T10:08:46Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:08:46Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:08:47Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:08:48Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:08:49Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:08:50Z DEBUG step duration: pki-tomcatd configure_renewal 3.85 sec 2020-06-17T10:08:50Z DEBUG [21/29]: Configure HTTP to proxy connections 2020-06-17T10:08:50Z DEBUG step duration: pki-tomcatd http_proxy 0.00 sec 2020-06-17T10:08:50Z DEBUG [22/29]: restarting certificate server 2020-06-17T10:08:50Z DEBUG Starting external process 2020-06-17T10:08:50Z DEBUG args=['/bin/systemctl', 'restart', 'pki-tomcatd@pki-tomcat.service'] 2020-06-17T10:09:06Z DEBUG Process finished, return code=0 2020-06-17T10:09:06Z DEBUG stdout= 2020-06-17T10:09:06Z DEBUG stderr= 2020-06-17T10:09:06Z DEBUG Starting external process 2020-06-17T10:09:06Z DEBUG args=['/bin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2020-06-17T10:09:06Z DEBUG Process finished, return code=0 2020-06-17T10:09:06Z DEBUG stdout=active 2020-06-17T10:09:06Z DEBUG stderr= 2020-06-17T10:09:06Z DEBUG wait_for_open_ports: localhost [8080, 8443] timeout 120 2020-06-17T10:09:06Z DEBUG waiting for port: 8080 2020-06-17T10:09:06Z DEBUG SUCCESS: port: 8080 2020-06-17T10:09:06Z DEBUG waiting for port: 8443 2020-06-17T10:09:06Z DEBUG SUCCESS: port: 8443 2020-06-17T10:09:06Z DEBUG Restart of pki-tomcatd@pki-tomcat.service complete 2020-06-17T10:09:06Z DEBUG step duration: pki-tomcatd restart_instance 16.48 sec 2020-06-17T10:09:06Z DEBUG [23/29]: updating IPA configuration 2020-06-17T10:09:06Z DEBUG step duration: pki-tomcatd update_ipa_conf 0.00 sec 2020-06-17T10:09:06Z DEBUG [24/29]: enabling CA instance 2020-06-17T10:09:06Z DEBUG Starting external process 2020-06-17T10:09:06Z DEBUG args=['/bin/systemctl', 'disable', 'pki-tomcatd.target'] 2020-06-17T10:09:06Z DEBUG Process finished, return code=0 2020-06-17T10:09:06Z DEBUG stdout= 2020-06-17T10:09:06Z DEBUG stderr= 2020-06-17T10:09:06Z DEBUG step duration: pki-tomcatd __enable_instance 0.24 sec 2020-06-17T10:09:06Z DEBUG [25/29]: migrating certificate profiles to LDAP 2020-06-17T10:09:06Z DEBUG Created connection context.ldap2_139849942680520 2020-06-17T10:09:06Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:09:06Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:09:07Z DEBUG Destroyed connection context.ldap2_139849942680520 2020-06-17T10:09:07Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:07Z DEBUG request body '' 2020-06-17T10:09:08Z DEBUG response status 200 2020-06-17T10:09:08Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=28FB01732FE8DE2E800ADDEC6562EB55; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:08 GMT 2020-06-17T10:09:08Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:08Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:08Z DEBUG request body 'desc=This certificate profile is for enrolling server certificates using CMC.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=Server Certificate Enrollment using CMC\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=.*CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.9.default.name=copy CN to SAN Default\nprofileId=caCMCserverCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:08Z DEBUG response status 409 2020-06-17T10:09:08Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:08 GMT 2020-06-17T10:09:08Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:08Z DEBUG Error migrating 'caCMCserverCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:08Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caCMCserverCert?action=enable 2020-06-17T10:09:08Z DEBUG request body '' 2020-06-17T10:09:08Z DEBUG response status 409 2020-06-17T10:09:08Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:08 GMT 2020-06-17T10:09:08Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:08Z DEBUG Failed to enable profile 'caCMCserverCert' (it is probably already enabled) 2020-06-17T10:09:08Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:08Z DEBUG request body '' 2020-06-17T10:09:08Z DEBUG response status 204 2020-06-17T10:09:08Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=EA3FCDD247B485609FC069D4BF903BA4; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:08 GMT 2020-06-17T10:09:08Z DEBUG response body (decoded): b'' 2020-06-17T10:09:08Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:08Z DEBUG request body '' 2020-06-17T10:09:08Z DEBUG response status 200 2020-06-17T10:09:08Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=DC9DDBE12085868FC62F017893D4758F; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:08 GMT 2020-06-17T10:09:08Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:08Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:08Z DEBUG request body 'desc=This certificate profile is for enrolling server certificates with ECC keys using CMC.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=Server Certificate wth ECC keys Enrollment using CMC\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=.*CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=EC\npolicyset.serverCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.9.default.name=copy CN to SAN Default\nprofileId=caCMCECserverCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:08Z DEBUG response status 409 2020-06-17T10:09:08Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:08 GMT 2020-06-17T10:09:08Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:08Z DEBUG Error migrating 'caCMCECserverCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:08Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caCMCECserverCert?action=enable 2020-06-17T10:09:08Z DEBUG request body '' 2020-06-17T10:09:09Z DEBUG response status 409 2020-06-17T10:09:09Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:08 GMT 2020-06-17T10:09:09Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:09Z DEBUG Failed to enable profile 'caCMCECserverCert' (it is probably already enabled) 2020-06-17T10:09:09Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:09Z DEBUG request body '' 2020-06-17T10:09:09Z DEBUG response status 204 2020-06-17T10:09:09Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=6E5E2772625723702F47ED3C61671125; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:08 GMT 2020-06-17T10:09:09Z DEBUG response body (decoded): b'' 2020-06-17T10:09:09Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:09Z DEBUG request body '' 2020-06-17T10:09:09Z DEBUG response status 200 2020-06-17T10:09:09Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=E61E53D17D75E2ECCFA669B5F8490B06; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:09 GMT 2020-06-17T10:09:09Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:09Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:09Z DEBUG request body 'desc=This certificate profile is for enrolling subsystem certificates with ECC keys using CMC.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=Subsystem Certificate Enrollment with ECC keys using CMC\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=EC\npolicyset.serverCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\nprofileId=caCMCECsubsystemCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:09Z DEBUG response status 409 2020-06-17T10:09:09Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:09 GMT 2020-06-17T10:09:09Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:09Z DEBUG Error migrating 'caCMCECsubsystemCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:09Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caCMCECsubsystemCert?action=enable 2020-06-17T10:09:09Z DEBUG request body '' 2020-06-17T10:09:09Z DEBUG response status 409 2020-06-17T10:09:09Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:09 GMT 2020-06-17T10:09:09Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:09Z DEBUG Failed to enable profile 'caCMCECsubsystemCert' (it is probably already enabled) 2020-06-17T10:09:09Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:09Z DEBUG request body '' 2020-06-17T10:09:09Z DEBUG response status 204 2020-06-17T10:09:09Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=566F84E6AED0CDBF78A460A89D8F3FE8; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:09 GMT 2020-06-17T10:09:09Z DEBUG response body (decoded): b'' 2020-06-17T10:09:09Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:09Z DEBUG request body '' 2020-06-17T10:09:09Z DEBUG response status 200 2020-06-17T10:09:09Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=DE9CBD2F0926D5CCDA1D1F36245BB04B; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:09 GMT 2020-06-17T10:09:09Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:09Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:09Z DEBUG request body 'desc=This certificate profile is for enrolling subsystem certificates using CMC.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=Subsystem Certificate Enrollment using CMC\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\nprofileId=caCMCsubsystemCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:09Z DEBUG response status 409 2020-06-17T10:09:09Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:09 GMT 2020-06-17T10:09:09Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:09Z DEBUG Error migrating 'caCMCsubsystemCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:09Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caCMCsubsystemCert?action=enable 2020-06-17T10:09:09Z DEBUG request body '' 2020-06-17T10:09:09Z DEBUG response status 409 2020-06-17T10:09:09Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:09 GMT 2020-06-17T10:09:09Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:09Z DEBUG Failed to enable profile 'caCMCsubsystemCert' (it is probably already enabled) 2020-06-17T10:09:09Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:09Z DEBUG request body '' 2020-06-17T10:09:09Z DEBUG response status 204 2020-06-17T10:09:09Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=A4AC2ADA75C3CB44865AA84735AA188F; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:09 GMT 2020-06-17T10:09:09Z DEBUG response body (decoded): b'' 2020-06-17T10:09:09Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:09Z DEBUG request body '' 2020-06-17T10:09:09Z DEBUG response status 200 2020-06-17T10:09:09Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=7C9F618100D3FA404A89468BC1C3AFFD; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:09 GMT 2020-06-17T10:09:09Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:09Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:09Z DEBUG request body 'desc=This certificate profile is for enrolling audit signing certificates using CMC.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=Audit Signing Certificate Enrollment using CMC\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=auditSigningCertSet\npolicyset.auditSigningCertSet.list=1,2,3,4,5,6,9\npolicyset.auditSigningCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.auditSigningCertSet.1.constraint.name=Subject Name Constraint\npolicyset.auditSigningCertSet.1.constraint.params.pattern=CN=.*\npolicyset.auditSigningCertSet.1.constraint.params.accept=true\npolicyset.auditSigningCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.auditSigningCertSet.1.default.name=Subject Name Default\npolicyset.auditSigningCertSet.1.default.params.name=\npolicyset.auditSigningCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.auditSigningCertSet.2.constraint.name=Validity Constraint\npolicyset.auditSigningCertSet.2.constraint.params.range=720\npolicyset.auditSigningCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.auditSigningCertSet.2.constraint.params.notAfterCheck=false\npolicyset.auditSigningCertSet.2.default.class_id=validityDefaultImpl\npolicyset.auditSigningCertSet.2.default.name=Validity Default\npolicyset.auditSigningCertSet.2.default.params.range=720\npolicyset.auditSigningCertSet.2.default.params.startTime=0\npolicyset.auditSigningCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.auditSigningCertSet.3.constraint.name=Key Constraint\npolicyset.auditSigningCertSet.3.constraint.params.keyType=-\npolicyset.auditSigningCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp521\npolicyset.auditSigningCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.auditSigningCertSet.3.default.name=Key Default\npolicyset.auditSigningCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.auditSigningCertSet.4.constraint.name=No Constraint\npolicyset.auditSigningCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.auditSigningCertSet.4.default.name=Authority Key Identifier Default\npolicyset.auditSigningCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.auditSigningCertSet.5.constraint.name=No Constraint\npolicyset.auditSigningCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.auditSigningCertSet.5.default.name=AIA Extension Default\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.auditSigningCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.auditSigningCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.auditSigningCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.auditSigningCertSet.6.default.name=Key Usage Default\npolicyset.auditSigningCertSet.6.default.params.keyUsageCritical=true\npolicyset.auditSigningCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.auditSigningCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.auditSigningCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.auditSigningCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.auditSigningCertSet.9.constraint.name=No Constraint\npolicyset.auditSigningCertSet.9.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.auditSigningCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.auditSigningCertSet.9.default.name=Signing Alg\npolicyset.auditSigningCertSet.9.default.params.signingAlg=-\nprofileId=caCMCauditSigningCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:09Z DEBUG response status 409 2020-06-17T10:09:09Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:09 GMT 2020-06-17T10:09:09Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:09Z DEBUG Error migrating 'caCMCauditSigningCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:09Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caCMCauditSigningCert?action=enable 2020-06-17T10:09:09Z DEBUG request body '' 2020-06-17T10:09:09Z DEBUG response status 409 2020-06-17T10:09:09Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:09 GMT 2020-06-17T10:09:09Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:09Z DEBUG Failed to enable profile 'caCMCauditSigningCert' (it is probably already enabled) 2020-06-17T10:09:09Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:09Z DEBUG request body '' 2020-06-17T10:09:09Z DEBUG response status 204 2020-06-17T10:09:09Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=34EBCD1C10B6B6F27C1A9509E78D4A90; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:09 GMT 2020-06-17T10:09:09Z DEBUG response body (decoded): b'' 2020-06-17T10:09:09Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:09Z DEBUG request body '' 2020-06-17T10:09:09Z DEBUG response status 200 2020-06-17T10:09:09Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=FB262EDF959C033429A37F313921D7FC; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:09 GMT 2020-06-17T10:09:09Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:09Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:09Z DEBUG request body 'desc=This certificate profile is for enrolling Certificate Authority certificates using CMC.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=Certificate Manager Signing Certificate Enrollment using CMC\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=caCertSet\npolicyset.caCertSet.list=1,2,3,4,5,6,8,9,10\npolicyset.caCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.caCertSet.1.constraint.name=Subject Name Constraint\npolicyset.caCertSet.1.constraint.params.pattern=CN=.*\npolicyset.caCertSet.1.constraint.params.accept=true\npolicyset.caCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.caCertSet.1.default.name=Subject Name Default\npolicyset.caCertSet.1.default.params.name=\npolicyset.caCertSet.2.constraint.class_id=caValidityConstraintImpl\npolicyset.caCertSet.2.constraint.name=CA Validity Constraint\npolicyset.caCertSet.2.constraint.params.range=7305\npolicyset.caCertSet.2.default.class_id=caValidityDefaultImpl\npolicyset.caCertSet.2.default.name=CA Certificate Validity Default\npolicyset.caCertSet.2.default.params.range=7305\npolicyset.caCertSet.2.default.params.startTime=0\npolicyset.caCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.caCertSet.3.constraint.name=Key Constraint\npolicyset.caCertSet.3.constraint.params.keyType=-\npolicyset.caCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.caCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.caCertSet.3.default.name=Key Default\npolicyset.caCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.4.constraint.name=No Constraint\npolicyset.caCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.caCertSet.4.default.name=Authority Key Identifier Default\npolicyset.caCertSet.5.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.caCertSet.5.constraint.name=Basic Constraint Extension Constraint\npolicyset.caCertSet.5.constraint.params.basicConstraintsCritical=true\npolicyset.caCertSet.5.constraint.params.basicConstraintsIsCA=true\npolicyset.caCertSet.5.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.caCertSet.5.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.caCertSet.5.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.caCertSet.5.default.name=Basic Constraints Extension Default\npolicyset.caCertSet.5.default.params.basicConstraintsCritical=true\npolicyset.caCertSet.5.default.params.basicConstraintsIsCA=true\npolicyset.caCertSet.5.default.params.basicConstraintsPathLen=-1\npolicyset.caCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.caCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.caCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.caCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.caCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.caCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyCertSign=true\npolicyset.caCertSet.6.constraint.params.keyUsageCrlSign=true\npolicyset.caCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.caCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.caCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.caCertSet.6.default.name=Key Usage Default\npolicyset.caCertSet.6.default.params.keyUsageCritical=true\npolicyset.caCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.caCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.caCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.caCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.caCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.caCertSet.6.default.params.keyUsageKeyCertSign=true\npolicyset.caCertSet.6.default.params.keyUsageCrlSign=true\npolicyset.caCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.caCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.caCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.8.constraint.name=No Constraint\npolicyset.caCertSet.8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.caCertSet.8.default.name=Subject Key Identifier Extension Default\npolicyset.caCertSet.8.default.params.critical=false\npolicyset.caCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.caCertSet.9.constraint.name=No Constraint\npolicyset.caCertSet.9.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.caCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.caCertSet.9.default.name=Signing Alg\npolicyset.caCertSet.9.default.params.signingAlg=-\npolicyset.caCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.10.constraint.name=No Constraint\npolicyset.caCertSet.10.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.caCertSet.10.default.name=AIA Extension Default\npolicyset.caCertSet.10.default.params.authInfoAccessADEnable_0=true\npolicyset.caCertSet.10.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.caCertSet.10.default.params.authInfoAccessADLocation_0=\npolicyset.caCertSet.10.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.caCertSet.10.default.params.authInfoAccessCritical=false\npolicyset.caCertSet.10.default.params.authInfoAccessNumADs=1\nprofileId=caCMCcaCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:09Z DEBUG response status 409 2020-06-17T10:09:09Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:09 GMT 2020-06-17T10:09:09Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:09Z DEBUG Error migrating 'caCMCcaCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:09Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caCMCcaCert?action=enable 2020-06-17T10:09:09Z DEBUG request body '' 2020-06-17T10:09:09Z DEBUG response status 409 2020-06-17T10:09:09Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:09 GMT 2020-06-17T10:09:09Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:09Z DEBUG Failed to enable profile 'caCMCcaCert' (it is probably already enabled) 2020-06-17T10:09:09Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:09Z DEBUG request body '' 2020-06-17T10:09:10Z DEBUG response status 204 2020-06-17T10:09:10Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=C489B38D91071B28D4BE817A30244176; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:09 GMT 2020-06-17T10:09:10Z DEBUG response body (decoded): b'' 2020-06-17T10:09:10Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:10Z DEBUG request body '' 2020-06-17T10:09:10Z DEBUG response status 200 2020-06-17T10:09:10Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=53FDB2D2BF13E5E5F08C96CDD7ECF43C; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:09 GMT 2020-06-17T10:09:10Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:10Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:10Z DEBUG request body 'desc=This certificate profile is for enrolling OCSP Responder signing certificates using CMC.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=OCSP Responder Signing Certificate Enrollment using CMC\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=ocspCertSet\npolicyset.ocspCertSet.list=1,2,3,4,5,6,8,9\npolicyset.ocspCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.ocspCertSet.1.constraint.name=Subject Name Constraint\npolicyset.ocspCertSet.1.constraint.params.pattern=CN=.*\npolicyset.ocspCertSet.1.constraint.params.accept=true\npolicyset.ocspCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.ocspCertSet.1.default.name=Subject Name Default\npolicyset.ocspCertSet.1.default.params.name=\npolicyset.ocspCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.ocspCertSet.2.constraint.name=Validity Constraint\npolicyset.ocspCertSet.2.constraint.params.range=720\npolicyset.ocspCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.ocspCertSet.2.constraint.params.notAfterCheck=false\npolicyset.ocspCertSet.2.default.class_id=validityDefaultImpl\npolicyset.ocspCertSet.2.default.name=Validity Default\npolicyset.ocspCertSet.2.default.params.range=720\npolicyset.ocspCertSet.2.default.params.startTime=0\npolicyset.ocspCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.ocspCertSet.3.constraint.name=Key Constraint\npolicyset.ocspCertSet.3.constraint.params.keyType=-\npolicyset.ocspCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.ocspCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.ocspCertSet.3.default.name=Key Default\npolicyset.ocspCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.ocspCertSet.4.constraint.name=No Constraint\npolicyset.ocspCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.ocspCertSet.4.default.name=Authority Key Identifier Default\npolicyset.ocspCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.ocspCertSet.5.constraint.name=No Constraint\npolicyset.ocspCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.ocspCertSet.5.default.name=AIA Extension Default\npolicyset.ocspCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.ocspCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.ocspCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.ocspCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.ocspCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.ocspCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.ocspCertSet.6.constraint.class_id=extendedKeyUsageExtConstraintImpl\npolicyset.ocspCertSet.6.constraint.name=Extended Key Usage Extension\npolicyset.ocspCertSet.6.constraint.params.exKeyUsageCritical=false\npolicyset.ocspCertSet.6.constraint.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.9\npolicyset.ocspCertSet.6.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.ocspCertSet.6.default.name=Extended Key Usage Default\npolicyset.ocspCertSet.6.default.params.exKeyUsageCritical=false\npolicyset.ocspCertSet.6.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.9\npolicyset.ocspCertSet.8.constraint.class_id=extensionConstraintImpl\npolicyset.ocspCertSet.8.constraint.name=No Constraint\npolicyset.ocspCertSet.8.constraint.params.extCritical=false\npolicyset.ocspCertSet.8.constraint.params.extOID=1.3.6.1.5.5.7.48.1.5\npolicyset.ocspCertSet.8.default.class_id=ocspNoCheckExtDefaultImpl\npolicyset.ocspCertSet.8.default.name=OCSP No Check Extension\npolicyset.ocspCertSet.8.default.params.ocspNoCheckCritical=false\npolicyset.ocspCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.ocspCertSet.9.constraint.name=No Constraint\npolicyset.ocspCertSet.9.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.ocspCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.ocspCertSet.9.default.name=Signing Alg\npolicyset.ocspCertSet.9.default.params.signingAlg=-\nprofileId=caCMCocspCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:10Z DEBUG response status 409 2020-06-17T10:09:10Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:09 GMT 2020-06-17T10:09:10Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:10Z DEBUG Error migrating 'caCMCocspCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:10Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caCMCocspCert?action=enable 2020-06-17T10:09:10Z DEBUG request body '' 2020-06-17T10:09:10Z DEBUG response status 409 2020-06-17T10:09:10Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:09 GMT 2020-06-17T10:09:10Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:10Z DEBUG Failed to enable profile 'caCMCocspCert' (it is probably already enabled) 2020-06-17T10:09:10Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:10Z DEBUG request body '' 2020-06-17T10:09:10Z DEBUG response status 204 2020-06-17T10:09:10Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=5D7B1D08358A2E3E3332076140402335; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:10 GMT 2020-06-17T10:09:10Z DEBUG response body (decoded): b'' 2020-06-17T10:09:10Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:10Z DEBUG request body '' 2020-06-17T10:09:10Z DEBUG response status 200 2020-06-17T10:09:10Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=B6FCAA37A9E685CA8301E90B94EC6D6C; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:10 GMT 2020-06-17T10:09:10Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:10Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:10Z DEBUG request body 'desc=This certificate profile is for enrolling Key Archival Authority transport certificates using CMC.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=Key Archival Authority Transport Certificate Enrollment using CMC\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=transportCertSet\npolicyset.transportCertSet.list=1,2,3,4,5,6,8\npolicyset.transportCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.transportCertSet.1.constraint.name=Subject Name Constraint\npolicyset.transportCertSet.1.constraint.params.pattern=CN=.*\npolicyset.transportCertSet.1.constraint.params.accept=true\npolicyset.transportCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.transportCertSet.1.default.name=Subject Name Default\npolicyset.transportCertSet.1.default.params.name=\npolicyset.transportCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.transportCertSet.2.constraint.name=Validity Constraint\npolicyset.transportCertSet.2.constraint.params.range=720\npolicyset.transportCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.transportCertSet.2.constraint.params.notAfterCheck=false\npolicyset.transportCertSet.2.default.class_id=validityDefaultImpl\npolicyset.transportCertSet.2.default.name=Validity Default\npolicyset.transportCertSet.2.default.params.range=720\npolicyset.transportCertSet.2.default.params.startTime=0\npolicyset.transportCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.transportCertSet.3.constraint.name=Key Constraint\npolicyset.transportCertSet.3.constraint.params.keyType=RSA\npolicyset.transportCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.transportCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.transportCertSet.3.default.name=Key Default\npolicyset.transportCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.transportCertSet.4.constraint.name=No Constraint\npolicyset.transportCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.transportCertSet.4.default.name=Authority Key Identifier Default\npolicyset.transportCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.transportCertSet.5.constraint.name=No Constraint\npolicyset.transportCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.transportCertSet.5.default.name=AIA Extension Default\npolicyset.transportCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.transportCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.transportCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.transportCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.transportCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.transportCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.transportCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.transportCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.transportCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.transportCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.transportCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.transportCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.transportCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.transportCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.transportCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.transportCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.transportCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.transportCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.transportCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.transportCertSet.6.default.name=Key Usage Default\npolicyset.transportCertSet.6.default.params.keyUsageCritical=true\npolicyset.transportCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.transportCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.transportCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.transportCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.transportCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.transportCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.transportCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.transportCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.transportCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.transportCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.transportCertSet.8.constraint.name=No Constraint\npolicyset.transportCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.transportCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.transportCertSet.8.default.name=Signing Alg\npolicyset.transportCertSet.8.default.params.signingAlg=-\nprofileId=caCMCkraTransportCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:10Z DEBUG response status 409 2020-06-17T10:09:10Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:10 GMT 2020-06-17T10:09:10Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:10Z DEBUG Error migrating 'caCMCkraTransportCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:10Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caCMCkraTransportCert?action=enable 2020-06-17T10:09:10Z DEBUG request body '' 2020-06-17T10:09:10Z DEBUG response status 409 2020-06-17T10:09:10Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:10 GMT 2020-06-17T10:09:10Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:10Z DEBUG Failed to enable profile 'caCMCkraTransportCert' (it is probably already enabled) 2020-06-17T10:09:10Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:10Z DEBUG request body '' 2020-06-17T10:09:10Z DEBUG response status 204 2020-06-17T10:09:10Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=0813CA55732F9ECAAC2A7210A8B93C1D; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:10 GMT 2020-06-17T10:09:10Z DEBUG response body (decoded): b'' 2020-06-17T10:09:10Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:10Z DEBUG request body '' 2020-06-17T10:09:10Z DEBUG response status 200 2020-06-17T10:09:10Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=3B45B8FC6E388298D28870286D80853E; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:10 GMT 2020-06-17T10:09:10Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:10Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:10Z DEBUG request body 'desc=This certificate profile is for enrolling KRA storage certificates using CMC\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=KRA storage Certificate Enrollment using CMC\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=drmStorageCertSet\npolicyset.drmStorageCertSet.list=1,2,3,4,5,6,9\npolicyset.drmStorageCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.drmStorageCertSet.1.constraint.name=Subject Name Constraint\npolicyset.drmStorageCertSet.1.constraint.params.pattern=CN=.*\npolicyset.drmStorageCertSet.1.constraint.params.accept=true\npolicyset.drmStorageCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.drmStorageCertSet.1.default.name=Subject Name Default\npolicyset.drmStorageCertSet.1.default.params.name=\npolicyset.drmStorageCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.drmStorageCertSet.2.constraint.name=Validity Constraint\npolicyset.drmStorageCertSet.2.constraint.params.range=720\npolicyset.drmStorageCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.drmStorageCertSet.2.constraint.params.notAfterCheck=false\npolicyset.drmStorageCertSet.2.default.class_id=validityDefaultImpl\npolicyset.drmStorageCertSet.2.default.name=Validity Default\npolicyset.drmStorageCertSet.2.default.params.range=720\npolicyset.drmStorageCertSet.2.default.params.startTime=0\npolicyset.drmStorageCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.drmStorageCertSet.3.constraint.name=Key Constraint\npolicyset.drmStorageCertSet.3.constraint.params.keyType=RSA\npolicyset.drmStorageCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.drmStorageCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.drmStorageCertSet.3.default.name=Key Default\npolicyset.drmStorageCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.drmStorageCertSet.4.constraint.name=No Constraint\npolicyset.drmStorageCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.drmStorageCertSet.4.default.name=Authority Key Identifier Default\npolicyset.drmStorageCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.drmStorageCertSet.5.constraint.name=No Constraint\npolicyset.drmStorageCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.drmStorageCertSet.5.default.name=AIA Extension Default\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.drmStorageCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.drmStorageCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.drmStorageCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.drmStorageCertSet.6.default.name=Key Usage Default\npolicyset.drmStorageCertSet.6.default.params.keyUsageCritical=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.drmStorageCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.drmStorageCertSet.9.constraint.name=No Constraint\npolicyset.drmStorageCertSet.9.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.drmStorageCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.drmStorageCertSet.9.default.name=Signing Alg\npolicyset.drmStorageCertSet.9.default.params.signingAlg=-\nprofileId=caCMCkraStorageCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:10Z DEBUG response status 409 2020-06-17T10:09:10Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:10 GMT 2020-06-17T10:09:10Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:10Z DEBUG Error migrating 'caCMCkraStorageCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:10Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caCMCkraStorageCert?action=enable 2020-06-17T10:09:10Z DEBUG request body '' 2020-06-17T10:09:10Z DEBUG response status 409 2020-06-17T10:09:10Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:10 GMT 2020-06-17T10:09:10Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:10Z DEBUG Failed to enable profile 'caCMCkraStorageCert' (it is probably already enabled) 2020-06-17T10:09:10Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:10Z DEBUG request body '' 2020-06-17T10:09:10Z DEBUG response status 204 2020-06-17T10:09:10Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=ACDA73B30C15F92BE103C92CFE04FF9D; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:10 GMT 2020-06-17T10:09:10Z DEBUG response body (decoded): b'' 2020-06-17T10:09:10Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:10Z DEBUG request body '' 2020-06-17T10:09:10Z DEBUG response status 200 2020-06-17T10:09:10Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=01865ADDB6D3BE928425E10BD3B72F1A; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:10 GMT 2020-06-17T10:09:10Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:10Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:10Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates.\nvisible=true\nenable=true\nenableBy=admin\nname=Manual User Dual-Use Certificate Enrollment\nauth.class_id=\ninput.list=i1,i2,i3\ninput.i1.class_id=keyGenInputImpl\ninput.i2.class_id=subjectNameInputImpl\ninput.i3.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=userCertSet\npolicyset.userCertSet.list=1,10,2,3,4,5,6,7,8,9\npolicyset.userCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.userCertSet.1.constraint.name=Subject Name Constraint\npolicyset.userCertSet.1.constraint.params.pattern=UID=.*\npolicyset.userCertSet.1.constraint.params.accept=true\npolicyset.userCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.userCertSet.1.default.name=Subject Name Default\npolicyset.userCertSet.1.default.params.name=\npolicyset.userCertSet.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.userCertSet.10.constraint.name=Renewal Grace Period Constraint\npolicyset.userCertSet.10.constraint.params.renewal.graceBefore=30\npolicyset.userCertSet.10.constraint.params.renewal.graceAfter=30\npolicyset.userCertSet.10.default.class_id=noDefaultImpl\npolicyset.userCertSet.10.default.name=No Default\npolicyset.userCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.userCertSet.2.constraint.name=Validity Constraint\npolicyset.userCertSet.2.constraint.params.range=365\npolicyset.userCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.userCertSet.2.constraint.params.notAfterCheck=false\npolicyset.userCertSet.2.default.class_id=validityDefaultImpl\npolicyset.userCertSet.2.default.name=Validity Default\npolicyset.userCertSet.2.default.params.range=180\npolicyset.userCertSet.2.default.params.startTime=0\npolicyset.userCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.userCertSet.3.constraint.name=Key Constraint\npolicyset.userCertSet.3.constraint.params.keyType=RSA\npolicyset.userCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.userCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.userCertSet.3.default.name=Key Default\npolicyset.userCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.4.constraint.name=No Constraint\npolicyset.userCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.userCertSet.4.default.name=Authority Key Identifier Default\npolicyset.userCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.5.constraint.name=No Constraint\npolicyset.userCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.userCertSet.5.default.name=AIA Extension Default\npolicyset.userCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.userCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.userCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.userCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.userCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.userCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.userCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.userCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.userCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.userCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.userCertSet.6.default.name=Key Usage Default\npolicyset.userCertSet.6.default.params.keyUsageCritical=true\npolicyset.userCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.7.constraint.name=No Constraint\npolicyset.userCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.userCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.userCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.userCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.userCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.8.constraint.name=No Constraint\npolicyset.userCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.userCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.userCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.userCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.userCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.userCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.userCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.userCertSet.9.constraint.name=No Constraint\npolicyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.userCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.userCertSet.9.default.name=Signing Alg\npolicyset.userCertSet.9.default.params.signingAlg=-\nprofileId=caUserCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:10Z DEBUG response status 409 2020-06-17T10:09:10Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:10 GMT 2020-06-17T10:09:10Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:10Z DEBUG Error migrating 'caUserCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:10Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caUserCert?action=enable 2020-06-17T10:09:10Z DEBUG request body '' 2020-06-17T10:09:10Z DEBUG response status 409 2020-06-17T10:09:10Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:10 GMT 2020-06-17T10:09:10Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:10Z DEBUG Failed to enable profile 'caUserCert' (it is probably already enabled) 2020-06-17T10:09:10Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:10Z DEBUG request body '' 2020-06-17T10:09:10Z DEBUG response status 204 2020-06-17T10:09:10Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=9A94652F5E7B23C44C7F57127B9A0167; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:10 GMT 2020-06-17T10:09:10Z DEBUG response body (decoded): b'' 2020-06-17T10:09:10Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:10Z DEBUG request body '' 2020-06-17T10:09:10Z DEBUG response status 200 2020-06-17T10:09:10Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=7658E31874AE57E94A48CB92919A0555; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:10 GMT 2020-06-17T10:09:10Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:10Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:10Z DEBUG request body 'desc=This certificate profile is for enrolling user ECC certificates.\nvisible=false\nenable=true\nenableBy=admin\nname=Manual User Dual-Use ECC Certificate Enrollment\nauth.class_id=\ninput.list=i1,i2,i3\ninput.i1.class_id=keyGenInputImpl\ninput.i2.class_id=subjectNameInputImpl\ninput.i3.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=userCertSet\npolicyset.userCertSet.list=1,10,2,3,4,5,6,7,8,9\npolicyset.userCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.userCertSet.1.constraint.name=Subject Name Constraint\npolicyset.userCertSet.1.constraint.params.pattern=UID=.*\npolicyset.userCertSet.1.constraint.params.accept=true\npolicyset.userCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.userCertSet.1.default.name=Subject Name Default\npolicyset.userCertSet.1.default.params.name=\npolicyset.userCertSet.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.userCertSet.10.constraint.name=Renewal Grace Period Constraint\npolicyset.userCertSet.10.constraint.params.renewal.graceBefore=30\npolicyset.userCertSet.10.constraint.params.renewal.graceAfter=30\npolicyset.userCertSet.10.default.class_id=noDefaultImpl\npolicyset.userCertSet.10.default.name=No Default\npolicyset.userCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.userCertSet.2.constraint.name=Validity Constraint\npolicyset.userCertSet.2.constraint.params.range=365\npolicyset.userCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.userCertSet.2.constraint.params.notAfterCheck=false\npolicyset.userCertSet.2.default.class_id=validityDefaultImpl\npolicyset.userCertSet.2.default.name=Validity Default\npolicyset.userCertSet.2.default.params.range=180\npolicyset.userCertSet.2.default.params.startTime=0\npolicyset.userCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.userCertSet.3.constraint.name=Key Constraint\npolicyset.userCertSet.3.constraint.params.keyType=EC\npolicyset.userCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.userCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.userCertSet.3.default.name=Key Default\npolicyset.userCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.4.constraint.name=No Constraint\npolicyset.userCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.userCertSet.4.default.name=Authority Key Identifier Default\npolicyset.userCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.5.constraint.name=No Constraint\npolicyset.userCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.userCertSet.5.default.name=AIA Extension Default\npolicyset.userCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.userCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.userCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.userCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.userCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.userCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.userCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.userCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.userCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.userCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.userCertSet.6.default.name=Key Usage Default\npolicyset.userCertSet.6.default.params.keyUsageCritical=true\npolicyset.userCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.userCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.7.constraint.name=No Constraint\npolicyset.userCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.userCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.userCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.userCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.userCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.8.constraint.name=No Constraint\npolicyset.userCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.userCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.userCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.userCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.userCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.userCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.userCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.userCertSet.9.constraint.name=No Constraint\npolicyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.userCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.userCertSet.9.default.name=Signing Alg\npolicyset.userCertSet.9.default.params.signingAlg=-\nprofileId=caECUserCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:10Z DEBUG response status 409 2020-06-17T10:09:10Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:10 GMT 2020-06-17T10:09:10Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:10Z DEBUG Error migrating 'caECUserCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:10Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caECUserCert?action=enable 2020-06-17T10:09:10Z DEBUG request body '' 2020-06-17T10:09:10Z DEBUG response status 409 2020-06-17T10:09:10Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:10 GMT 2020-06-17T10:09:10Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:10Z DEBUG Failed to enable profile 'caECUserCert' (it is probably already enabled) 2020-06-17T10:09:10Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:10Z DEBUG request body '' 2020-06-17T10:09:11Z DEBUG response status 204 2020-06-17T10:09:11Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=32ED15E8945FF99C5638FEEF2A346DED; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:10 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'' 2020-06-17T10:09:11Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:11Z DEBUG request body '' 2020-06-17T10:09:11Z DEBUG response status 200 2020-06-17T10:09:11Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=59D067678574F5E6B96CF67A778E7AAD; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:10 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:11Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:11Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates with S/MIME capabilities extension - OID: 1.2.840.113549.1.9.15\nvisible=true\nenable=true\nenableBy=admin\nname=Manual User Dual-Use S/MIME capabilities Certificate Enrollment\nauth.class_id=\ninput.list=i1,i2,i3\ninput.i1.class_id=keyGenInputImpl\ninput.i2.class_id=subjectNameInputImpl\ninput.i3.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=userCertSet\npolicyset.userCertSet.list=1,10,2,3,4,5,6,7,8,9,11\npolicyset.userCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.userCertSet.1.constraint.name=Subject Name Constraint\npolicyset.userCertSet.1.constraint.params.pattern=UID=.*\npolicyset.userCertSet.1.constraint.params.accept=true\npolicyset.userCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.userCertSet.1.default.name=Subject Name Default\npolicyset.userCertSet.1.default.params.name=\npolicyset.userCertSet.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.userCertSet.10.constraint.name=Renewal Grace Period Constraint\npolicyset.userCertSet.10.constraint.params.renewal.graceBefore=30\npolicyset.userCertSet.10.constraint.params.renewal.graceAfter=30\npolicyset.userCertSet.10.default.class_id=noDefaultImpl\npolicyset.userCertSet.10.default.name=No Default\npolicyset.userCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.userCertSet.2.constraint.name=Validity Constraint\npolicyset.userCertSet.2.constraint.params.range=365\npolicyset.userCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.userCertSet.2.constraint.params.notAfterCheck=false\npolicyset.userCertSet.2.default.class_id=validityDefaultImpl\npolicyset.userCertSet.2.default.name=Validity Default\npolicyset.userCertSet.2.default.params.range=180\npolicyset.userCertSet.2.default.params.startTime=0\npolicyset.userCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.userCertSet.3.constraint.name=Key Constraint\npolicyset.userCertSet.3.constraint.params.keyType=-\npolicyset.userCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.userCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.userCertSet.3.default.name=Key Default\npolicyset.userCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.4.constraint.name=No Constraint\npolicyset.userCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.userCertSet.4.default.name=Authority Key Identifier Default\npolicyset.userCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.5.constraint.name=No Constraint\npolicyset.userCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.userCertSet.5.default.name=AIA Extension Default\npolicyset.userCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.userCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.userCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.userCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.userCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.userCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.userCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.userCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.userCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.userCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.userCertSet.6.default.name=Key Usage Default\npolicyset.userCertSet.6.default.params.keyUsageCritical=true\npolicyset.userCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.7.constraint.name=No Constraint\npolicyset.userCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.userCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.userCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.userCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.userCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.8.constraint.name=No Constraint\npolicyset.userCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.userCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.userCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.userCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.userCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.userCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.userCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.userCertSet.9.constraint.name=No Constraint\npolicyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.userCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.userCertSet.9.default.name=Signing Alg\npolicyset.userCertSet.9.default.params.signingAlg=-\npolicyset.userCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.11.constraint.name=No Constraint\npolicyset.userCertSet.11.default.class_id=genericExtDefaultImpl\npolicyset.userCertSet.11.default.name=Generic Extension\npolicyset.userCertSet.11.default.params.genericExtOID=1.2.840.113549.1.9.15\npolicyset.userCertSet.11.default.params.genericExtData=3067300B06092A864886F70D010105300B06092A864886F70D01010B300B06092A864886F70D01010C300B06092A864886F70D01010D300A06082A864886F70D0307300B0609608648016503040102300B060960864801650304012A300B06092A864886F70D010101\nprofileId=caUserSMIMEcapCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:11Z DEBUG response status 409 2020-06-17T10:09:11Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:10 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:11Z DEBUG Error migrating 'caUserSMIMEcapCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:11Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caUserSMIMEcapCert?action=enable 2020-06-17T10:09:11Z DEBUG request body '' 2020-06-17T10:09:11Z DEBUG response status 409 2020-06-17T10:09:11Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:10 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:11Z DEBUG Failed to enable profile 'caUserSMIMEcapCert' (it is probably already enabled) 2020-06-17T10:09:11Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:11Z DEBUG request body '' 2020-06-17T10:09:11Z DEBUG response status 204 2020-06-17T10:09:11Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=AB16F122436F67A1B266EDB435232EE0; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:10 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'' 2020-06-17T10:09:11Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:11Z DEBUG request body '' 2020-06-17T10:09:11Z DEBUG response status 200 2020-06-17T10:09:11Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=14305C6381A7884AED23DECC88A43D56; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:11Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:11Z DEBUG request body 'desc=This certificate profile is for enrolling dual user certificates. It works only with Netscape 7.0 or later.\nvisible=false\nenable=true\nenableBy=admin\nname=Manual User Signing & Encryption Certificates Enrollment\nauth.class_id=\ninput.list=i1,i2,i3\ninput.i1.class_id=dualKeyGenInputImpl\ninput.i2.class_id=subjectNameInputImpl\ninput.i3.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=encryptionCertSet,signingCertSet\npolicyset.encryptionCertSet.list=1,2,3,4,5,6,7,8,9\npolicyset.encryptionCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.encryptionCertSet.1.constraint.name=Subject Name Constraint\npolicyset.encryptionCertSet.1.constraint.params.pattern=UID=.*\npolicyset.encryptionCertSet.1.constraint.params.accept=true\npolicyset.encryptionCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.encryptionCertSet.1.default.name=Subject Name Default\npolicyset.encryptionCertSet.1.default.params.name=\npolicyset.encryptionCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.encryptionCertSet.2.constraint.name=Validity Constraint\npolicyset.encryptionCertSet.2.constraint.params.range=365\npolicyset.encryptionCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.encryptionCertSet.2.constraint.params.notAfterCheck=false\npolicyset.encryptionCertSet.2.default.class_id=validityDefaultImpl\npolicyset.encryptionCertSet.2.default.name=Validity Default\npolicyset.encryptionCertSet.2.default.params.range=180\npolicyset.encryptionCertSet.2.default.params.startTime=0\npolicyset.encryptionCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.encryptionCertSet.3.constraint.name=Key Constraint\npolicyset.encryptionCertSet.3.constraint.params.keyType=RSA\npolicyset.encryptionCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.encryptionCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.encryptionCertSet.3.default.name=Key Default\npolicyset.encryptionCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.4.constraint.name=No Constraint\npolicyset.encryptionCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.encryptionCertSet.4.default.name=Authority Key Identifier Default\npolicyset.encryptionCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.5.constraint.name=No Constraint\npolicyset.encryptionCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.encryptionCertSet.5.default.name=AIA Extension Default\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.encryptionCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.encryptionCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.encryptionCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.encryptionCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.encryptionCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.encryptionCertSet.6.constraint.params.keyUsageDigitalSignature=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.encryptionCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.encryptionCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.encryptionCertSet.6.default.name=Key Usage Default\npolicyset.encryptionCertSet.6.default.params.keyUsageCritical=true\npolicyset.encryptionCertSet.6.default.params.keyUsageDigitalSignature=false\npolicyset.encryptionCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.encryptionCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.encryptionCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.encryptionCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.encryptionCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.encryptionCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.encryptionCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.encryptionCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.encryptionCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.7.constraint.name=No Constraint\npolicyset.encryptionCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.encryptionCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.encryptionCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.encryptionCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.encryptionCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.8.constraint.name=No Constraint\npolicyset.encryptionCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.encryptionCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.encryptionCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.encryptionCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.encryptionCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.encryptionCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.encryptionCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.encryptionCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.encryptionCertSet.9.constraint.name=No Constraint\npolicyset.encryptionCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.encryptionCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.encryptionCertSet.9.default.name=Signing Alg\npolicyset.encryptionCertSet.9.default.params.signingAlg=-\npolicyset.signingCertSet.list=1,2,3,4,6,7,8,9\npolicyset.signingCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.signingCertSet.1.constraint.name=Subject Name Constraint\npolicyset.signingCertSet.1.constraint.params.pattern=UID=.*\npolicyset.signingCertSet.1.constraint.params.accept=true\npolicyset.signingCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.signingCertSet.1.default.name=Subject Name Default\npolicyset.signingCertSet.1.default.params.name=\npolicyset.signingCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.signingCertSet.2.constraint.name=Validity Constraint\npolicyset.signingCertSet.2.constraint.params.range=365\npolicyset.signingCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.signingCertSet.2.constraint.params.notAfterCheck=false\npolicyset.signingCertSet.2.default.class_id=validityDefaultImpl\npolicyset.signingCertSet.2.default.name=Validity Default\npolicyset.signingCertSet.2.default.params.range=180\npolicyset.signingCertSet.2.default.params.startTime=0\npolicyset.signingCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.signingCertSet.3.constraint.name=Key Constraint\npolicyset.signingCertSet.3.constraint.params.keyType=RSA\npolicyset.signingCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.signingCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.signingCertSet.3.default.name=Key Default\npolicyset.signingCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.4.constraint.name=No Constraint\npolicyset.signingCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.signingCertSet.4.default.name=Authority Key Identifier Default\npolicyset.signingCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.signingCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.signingCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.signingCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.signingCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.signingCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.signingCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.signingCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.signingCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.signingCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.signingCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.signingCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.signingCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.signingCertSet.6.default.name=Key Usage Default\npolicyset.signingCertSet.6.default.params.keyUsageCritical=true\npolicyset.signingCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.signingCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.signingCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.signingCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.signingCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.signingCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.signingCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.signingCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.signingCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.signingCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.7.constraint.name=No Constraint\npolicyset.signingCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.signingCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.signingCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.signingCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.signingCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.8.constraint.name=No Constraint\npolicyset.signingCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.signingCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.signingCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.signingCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.signingCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.signingCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.signingCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.signingCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.signingCertSet.9.constraint.name=No Constraint\npolicyset.signingCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.signingCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.signingCertSet.9.default.name=Signing Alg\npolicyset.signingCertSet.9.default.params.signingAlg=-\npolicyset.signingCertSet.9.default.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\nprofileId=caDualCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:11Z DEBUG response status 409 2020-06-17T10:09:11Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:11Z DEBUG Error migrating 'caDualCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:11Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caDualCert?action=enable 2020-06-17T10:09:11Z DEBUG request body '' 2020-06-17T10:09:11Z DEBUG response status 409 2020-06-17T10:09:11Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:11Z DEBUG Failed to enable profile 'caDualCert' (it is probably already enabled) 2020-06-17T10:09:11Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:11Z DEBUG request body '' 2020-06-17T10:09:11Z DEBUG response status 204 2020-06-17T10:09:11Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=8343406575E191267704BD8FDD054CD0; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'' 2020-06-17T10:09:11Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:11Z DEBUG request body '' 2020-06-17T10:09:11Z DEBUG response status 200 2020-06-17T10:09:11Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=B6E1BB519109AF806F211042CD478021; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:11Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:11Z DEBUG request body 'desc=This certificate profile is for enrolling dual user certificates. It works only with Netscape 7.0 or later.\nvisible=true\nenable=false\nenableBy=admin\nname=Directory-authenticated User Signing & Encryption Certificates Enrollment\nauth.instance_id=UserDirEnrollment\ninput.list=i1,i2,i3\ninput.i1.class_id=dualKeyGenInputImpl\ninput.i2.class_id=subjectNameInputImpl\ninput.i3.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=encryptionCertSet,signingCertSet\npolicyset.encryptionCertSet.list=1,2,3,4,5,6,7,8,9\npolicyset.encryptionCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.encryptionCertSet.1.constraint.name=Subject Name Constraint\npolicyset.encryptionCertSet.1.constraint.params.pattern=UID=.*\npolicyset.encryptionCertSet.1.constraint.params.accept=true\npolicyset.encryptionCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.encryptionCertSet.1.default.name=Subject Name Default\npolicyset.encryptionCertSet.1.default.params.name=\npolicyset.encryptionCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.encryptionCertSet.2.constraint.name=Validity Constraint\npolicyset.encryptionCertSet.2.constraint.params.range=365\npolicyset.encryptionCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.encryptionCertSet.2.constraint.params.notAfterCheck=false\npolicyset.encryptionCertSet.2.default.class_id=validityDefaultImpl\npolicyset.encryptionCertSet.2.default.name=Validity Default\npolicyset.encryptionCertSet.2.default.params.range=180\npolicyset.encryptionCertSet.2.default.params.startTime=0\npolicyset.encryptionCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.encryptionCertSet.3.constraint.name=Key Constraint\npolicyset.encryptionCertSet.3.constraint.params.keyType=RSA\npolicyset.encryptionCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.encryptionCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.encryptionCertSet.3.default.name=Key Default\npolicyset.encryptionCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.4.constraint.name=No Constraint\npolicyset.encryptionCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.encryptionCertSet.4.default.name=Authority Key Identifier Default\npolicyset.encryptionCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.5.constraint.name=No Constraint\npolicyset.encryptionCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.encryptionCertSet.5.default.name=AIA Extension Default\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.encryptionCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.encryptionCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.encryptionCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.encryptionCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.encryptionCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.encryptionCertSet.6.constraint.params.keyUsageDigitalSignature=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.encryptionCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.encryptionCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.encryptionCertSet.6.default.name=Key Usage Default\npolicyset.encryptionCertSet.6.default.params.keyUsageCritical=true\npolicyset.encryptionCertSet.6.default.params.keyUsageDigitalSignature=false\npolicyset.encryptionCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.encryptionCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.encryptionCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.encryptionCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.encryptionCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.encryptionCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.encryptionCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.encryptionCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.encryptionCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.7.constraint.name=No Constraint\npolicyset.encryptionCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.encryptionCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.encryptionCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.encryptionCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.encryptionCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.8.constraint.name=No Constraint\npolicyset.encryptionCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.encryptionCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.encryptionCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.encryptionCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.encryptionCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.encryptionCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.encryptionCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.encryptionCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.encryptionCertSet.9.constraint.name=No Constraint\npolicyset.encryptionCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA384withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.encryptionCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.encryptionCertSet.9.default.name=Signing Alg\npolicyset.encryptionCertSet.9.default.params.signingAlg=-\npolicyset.signingCertSet.list=1,2,3,4,6,7,8,9\npolicyset.signingCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.signingCertSet.1.constraint.name=Subject Name Constraint\npolicyset.signingCertSet.1.constraint.params.pattern=UID=.*\npolicyset.signingCertSet.1.constraint.params.accept=true\npolicyset.signingCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.signingCertSet.1.default.name=Subject Name Default\npolicyset.signingCertSet.1.default.params.name=\npolicyset.signingCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.signingCertSet.2.constraint.name=Validity Constraint\npolicyset.signingCertSet.2.constraint.params.range=365\npolicyset.signingCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.signingCertSet.2.constraint.params.notAfterCheck=false\npolicyset.signingCertSet.2.default.class_id=validityDefaultImpl\npolicyset.signingCertSet.2.default.name=Validity Default\npolicyset.signingCertSet.2.default.params.range=180\npolicyset.signingCertSet.2.default.params.startTime=0\npolicyset.signingCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.signingCertSet.3.constraint.name=Key Constraint\npolicyset.signingCertSet.3.constraint.params.keyType=RSA\npolicyset.signingCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.signingCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.signingCertSet.3.default.name=Key Default\npolicyset.signingCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.4.constraint.name=No Constraint\npolicyset.signingCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.signingCertSet.4.default.name=Authority Key Identifier Default\npolicyset.signingCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.signingCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.signingCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.signingCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.signingCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.signingCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.signingCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.signingCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.signingCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.signingCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.signingCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.signingCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.signingCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.signingCertSet.6.default.name=Key Usage Default\npolicyset.signingCertSet.6.default.params.keyUsageCritical=true\npolicyset.signingCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.signingCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.signingCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.signingCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.signingCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.signingCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.signingCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.signingCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.signingCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.signingCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.7.constraint.name=No Constraint\npolicyset.signingCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.signingCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.signingCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.signingCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.signingCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.8.constraint.name=No Constraint\npolicyset.signingCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.signingCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.signingCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.signingCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.signingCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.signingCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.signingCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.signingCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.signingCertSet.9.constraint.name=No Constraint\npolicyset.signingCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.signingCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.signingCertSet.9.default.name=Signing Alg\npolicyset.signingCertSet.9.default.params.signingAlg=-\npolicyset.signingCertSet.9.default.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\nprofileId=caDirBasedDualCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:11Z DEBUG response status 409 2020-06-17T10:09:11Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:11Z DEBUG Error migrating 'caDirBasedDualCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:11Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caDirBasedDualCert?action=enable 2020-06-17T10:09:11Z DEBUG request body '' 2020-06-17T10:09:11Z DEBUG response status 204 2020-06-17T10:09:11Z DEBUG response headers Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'' 2020-06-17T10:09:11Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:11Z DEBUG request body '' 2020-06-17T10:09:11Z DEBUG response status 204 2020-06-17T10:09:11Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=B2734B92894C002A6301E022D0C2F892; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'' 2020-06-17T10:09:11Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:11Z DEBUG request body '' 2020-06-17T10:09:11Z DEBUG response status 200 2020-06-17T10:09:11Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=658DC7B709B424E3DD834F6DDF57CCB5; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:11Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:11Z DEBUG request body "desc=This certificate profile is for enrolling Administrator's certificates suitable for use by clients such as browsers.\nvisible=true\nenable=true\nenableBy=admin\nauth.instance_id=\nname=Manual Administrator Certificate Enrollment\ninput.list=i1,i2,i3\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\ninput.i3.class_id=subjectDNInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=adminCertSet\npolicyset.adminCertSet.list=1,2,3,4,5,6,7,8\npolicyset.adminCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.adminCertSet.1.constraint.name=Subject Name Constraint\npolicyset.adminCertSet.1.constraint.params.pattern=.*\npolicyset.adminCertSet.1.constraint.params.accept=true\npolicyset.adminCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.adminCertSet.1.default.name=Subject Name Default\npolicyset.adminCertSet.1.default.params.name=\npolicyset.adminCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.adminCertSet.2.constraint.name=Validity Constraint\npolicyset.adminCertSet.2.constraint.params.range=365\npolicyset.adminCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.adminCertSet.2.constraint.params.notAfterCheck=false\npolicyset.adminCertSet.2.default.class_id=validityDefaultImpl\npolicyset.adminCertSet.2.default.name=Validity Default\npolicyset.adminCertSet.2.default.params.range=365\npolicyset.adminCertSet.2.default.params.startTime=0\npolicyset.adminCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.adminCertSet.3.constraint.name=Key Constraint\npolicyset.adminCertSet.3.constraint.params.keyType=RSA\npolicyset.adminCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.adminCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.adminCertSet.3.default.name=Key Default\npolicyset.adminCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.4.constraint.name=No Constraint\npolicyset.adminCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.adminCertSet.4.default.name=Authority Key Identifier Default\npolicyset.adminCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.5.constraint.name=No Constraint\npolicyset.adminCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.adminCertSet.5.default.name=AIA Extension Default\npolicyset.adminCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.adminCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.adminCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.adminCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.adminCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.adminCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.adminCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.adminCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.adminCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.adminCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.adminCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.adminCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.adminCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.adminCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.adminCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.adminCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.adminCertSet.6.default.name=Key Usage Default\npolicyset.adminCertSet.6.default.params.keyUsageCritical=true\npolicyset.adminCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.adminCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.adminCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.adminCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.adminCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.adminCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.adminCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.adminCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.adminCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.adminCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.7.constraint.name=No Constraint\npolicyset.adminCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.adminCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.adminCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.adminCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.adminCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.adminCertSet.8.constraint.name=No Constraint\npolicyset.adminCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.adminCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.adminCertSet.8.default.name=Signing Alg\npolicyset.adminCertSet.8.default.params.signingAlg=-\nprofileId=AdminCert\nclassId=caEnrollImpl\n" 2020-06-17T10:09:11Z DEBUG response status 409 2020-06-17T10:09:11Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:11Z DEBUG Error migrating 'AdminCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:11Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/AdminCert?action=enable 2020-06-17T10:09:11Z DEBUG request body '' 2020-06-17T10:09:11Z DEBUG response status 409 2020-06-17T10:09:11Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:11Z DEBUG Failed to enable profile 'AdminCert' (it is probably already enabled) 2020-06-17T10:09:11Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:11Z DEBUG request body '' 2020-06-17T10:09:11Z DEBUG response status 204 2020-06-17T10:09:11Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=4E0D74EAD717F0D3E63E625EB5FF216C; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'' 2020-06-17T10:09:11Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:11Z DEBUG request body '' 2020-06-17T10:09:11Z DEBUG response status 200 2020-06-17T10:09:11Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=8FBE0C5AB00E9DC6432BD629E6D89BD6; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:11Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:11Z DEBUG request body "desc=This certificate profile is for enrolling Administrator's certificates with ECC keys suitable for use by clients such as browsers.\nvisible=true\nenable=true\nenableBy=admin\nauth.instance_id=\nname=Manual Administrator Certificate Enrollment with ECC keys\ninput.list=i1,i2,i3\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\ninput.i3.class_id=subjectDNInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=adminCertSet\npolicyset.adminCertSet.list=1,2,3,4,5,6,7,8\npolicyset.adminCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.adminCertSet.1.constraint.name=Subject Name Constraint\npolicyset.adminCertSet.1.constraint.params.pattern=.*\npolicyset.adminCertSet.1.constraint.params.accept=true\npolicyset.adminCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.adminCertSet.1.default.name=Subject Name Default\npolicyset.adminCertSet.1.default.params.name=\npolicyset.adminCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.adminCertSet.2.constraint.name=Validity Constraint\npolicyset.adminCertSet.2.constraint.params.range=365\npolicyset.adminCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.adminCertSet.2.constraint.params.notAfterCheck=false\npolicyset.adminCertSet.2.default.class_id=validityDefaultImpl\npolicyset.adminCertSet.2.default.name=Validity Default\npolicyset.adminCertSet.2.default.params.range=365\npolicyset.adminCertSet.2.default.params.startTime=0\npolicyset.adminCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.adminCertSet.3.constraint.name=Key Constraint\npolicyset.adminCertSet.3.constraint.params.keyType=-\npolicyset.adminCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.adminCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.adminCertSet.3.default.name=Key Default\npolicyset.adminCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.4.constraint.name=No Constraint\npolicyset.adminCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.adminCertSet.4.default.name=Authority Key Identifier Default\npolicyset.adminCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.5.constraint.name=No Constraint\npolicyset.adminCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.adminCertSet.5.default.name=AIA Extension Default\npolicyset.adminCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.adminCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.adminCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.adminCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.adminCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.adminCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.adminCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.adminCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.adminCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.adminCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.adminCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.adminCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.adminCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.adminCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.adminCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.adminCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.adminCertSet.6.default.name=Key Usage Default\npolicyset.adminCertSet.6.default.params.keyUsageCritical=true\npolicyset.adminCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.adminCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.adminCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.adminCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.adminCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.adminCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.adminCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.adminCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.adminCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.adminCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.7.constraint.name=No Constraint\npolicyset.adminCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.adminCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.adminCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.adminCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.adminCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.adminCertSet.8.constraint.name=No Constraint\npolicyset.adminCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.adminCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.adminCertSet.8.default.name=Signing Alg\npolicyset.adminCertSet.8.default.params.signingAlg=-\nprofileId=ECAdminCert\nclassId=caEnrollImpl\n" 2020-06-17T10:09:11Z DEBUG response status 409 2020-06-17T10:09:11Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:11Z DEBUG Error migrating 'ECAdminCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:11Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/ECAdminCert?action=enable 2020-06-17T10:09:11Z DEBUG request body '' 2020-06-17T10:09:11Z DEBUG response status 409 2020-06-17T10:09:11Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:11Z DEBUG Failed to enable profile 'ECAdminCert' (it is probably already enabled) 2020-06-17T10:09:11Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:11Z DEBUG request body '' 2020-06-17T10:09:11Z DEBUG response status 204 2020-06-17T10:09:11Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=076C17E809FD0B1F75F514A4C46BB87E; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'' 2020-06-17T10:09:11Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:11Z DEBUG request body '' 2020-06-17T10:09:11Z DEBUG response status 200 2020-06-17T10:09:11Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=9424555DD4D89CD5779CB3D112953B47; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:11Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:11Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:11Z DEBUG request body 'desc=This profile is for enrolling audit log signing certificates\nvisible=true\nenable=true\nenableBy=admin\nauth.class_id=\nname=Manual Log Signing Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=caLogSigningSet\npolicyset.caLogSigningSet.list=1,2,3,4,6,8,9\npolicyset.caLogSigningSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.caLogSigningSet.1.constraint.name=Subject Name Constraint\npolicyset.caLogSigningSet.1.constraint.params.pattern=CN=.*\npolicyset.caLogSigningSet.1.constraint.params.accept=true\npolicyset.caLogSigningSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.caLogSigningSet.1.default.name=Subject Name Default\npolicyset.caLogSigningSet.1.default.params.name=\npolicyset.caLogSigningSet.2.constraint.class_id=validityConstraintImpl\npolicyset.caLogSigningSet.2.constraint.name=Validity Constraint\npolicyset.caLogSigningSet.2.constraint.params.range=720\npolicyset.caLogSigningSet.2.constraint.params.notBeforeCheck=false\npolicyset.caLogSigningSet.2.constraint.params.notAfterCheck=false\npolicyset.caLogSigningSet.2.default.class_id=validityDefaultImpl\npolicyset.caLogSigningSet.2.default.name=Validity Default\npolicyset.caLogSigningSet.2.default.params.range=720\npolicyset.caLogSigningSet.2.default.params.startTime=0\npolicyset.caLogSigningSet.3.constraint.class_id=keyConstraintImpl\npolicyset.caLogSigningSet.3.constraint.name=Key Constraint\npolicyset.caLogSigningSet.3.constraint.params.keyType=-\npolicyset.caLogSigningSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp521\npolicyset.caLogSigningSet.3.default.class_id=userKeyDefaultImpl\npolicyset.caLogSigningSet.3.default.name=Key Default\npolicyset.caLogSigningSet.4.constraint.class_id=noConstraintImpl\npolicyset.caLogSigningSet.4.constraint.name=No Constraint\npolicyset.caLogSigningSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.caLogSigningSet.4.default.name=Authority Key Identifier Default\npolicyset.caLogSigningSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.caLogSigningSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.caLogSigningSet.6.constraint.params.keyUsageCritical=true\npolicyset.caLogSigningSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.caLogSigningSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.caLogSigningSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.caLogSigningSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.caLogSigningSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.caLogSigningSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.caLogSigningSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.caLogSigningSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.caLogSigningSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.caLogSigningSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.caLogSigningSet.6.default.name=Key Usage Default\npolicyset.caLogSigningSet.6.default.params.keyUsageCritical=true\npolicyset.caLogSigningSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.caLogSigningSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.caLogSigningSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.caLogSigningSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.caLogSigningSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.caLogSigningSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.caLogSigningSet.6.default.params.keyUsageCrlSign=false\npolicyset.caLogSigningSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.caLogSigningSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.caLogSigningSet.8.constraint.class_id=noConstraintImpl\npolicyset.caLogSigningSet.8.constraint.name=No Constraint\npolicyset.caLogSigningSet.8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.caLogSigningSet.8.default.name=Subject Key Identifier Extension Default\npolicyset.caLogSigningSet.8.default.params.critical=false\npolicyset.caLogSigningSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.caLogSigningSet.9.constraint.name=No Constraint\npolicyset.caLogSigningSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.caLogSigningSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.caLogSigningSet.9.default.name=Signing Alg\npolicyset.caLogSigningSet.9.default.params.signingAlg=-\nprofileId=caSignedLogCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:12Z DEBUG response status 409 2020-06-17T10:09:12Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:12Z DEBUG Error migrating 'caSignedLogCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:12Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caSignedLogCert?action=enable 2020-06-17T10:09:12Z DEBUG request body '' 2020-06-17T10:09:12Z DEBUG response status 409 2020-06-17T10:09:12Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:12Z DEBUG Failed to enable profile 'caSignedLogCert' (it is probably already enabled) 2020-06-17T10:09:12Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:12Z DEBUG request body '' 2020-06-17T10:09:12Z DEBUG response status 204 2020-06-17T10:09:12Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=480575581B0C3B9BAD38F8E91F16A6BF; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'' 2020-06-17T10:09:12Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:12Z DEBUG request body '' 2020-06-17T10:09:12Z DEBUG response status 200 2020-06-17T10:09:12Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=18245DC1010516290E70D738CB003231; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:12Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:12Z DEBUG request body 'desc=This certificate profile is for enrolling TPS server certificates.\nvisible=true\nenable=true\nenableBy=admin\nauth.class_id=\nname=Manual TPS Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=-\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\nprofileId=caTPSCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:12Z DEBUG response status 409 2020-06-17T10:09:12Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:12Z DEBUG Error migrating 'caTPSCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:12Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caTPSCert?action=enable 2020-06-17T10:09:12Z DEBUG request body '' 2020-06-17T10:09:12Z DEBUG response status 409 2020-06-17T10:09:12Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:11 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:12Z DEBUG Failed to enable profile 'caTPSCert' (it is probably already enabled) 2020-06-17T10:09:12Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:12Z DEBUG request body '' 2020-06-17T10:09:12Z DEBUG response status 204 2020-06-17T10:09:12Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=36A0883EC9C01032728A94A5AFD47B04; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'' 2020-06-17T10:09:12Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:12Z DEBUG request body '' 2020-06-17T10:09:12Z DEBUG response status 200 2020-06-17T10:09:12Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=80AE14DE1968B3A13EE04EE50F33AC8E; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:12Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:12Z DEBUG request body 'desc=This certificate profile is for enrolling router certificates.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=RA Agent-Authenticated Router Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\nprofileId=caRARouterCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:12Z DEBUG response status 409 2020-06-17T10:09:12Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:12Z DEBUG Error migrating 'caRARouterCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:12Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caRARouterCert?action=enable 2020-06-17T10:09:12Z DEBUG request body '' 2020-06-17T10:09:12Z DEBUG response status 409 2020-06-17T10:09:12Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:12Z DEBUG Failed to enable profile 'caRARouterCert' (it is probably already enabled) 2020-06-17T10:09:12Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:12Z DEBUG request body '' 2020-06-17T10:09:12Z DEBUG response status 204 2020-06-17T10:09:12Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=D1AD8822B6BFD4086E4B2F53C43828E4; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'' 2020-06-17T10:09:12Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:12Z DEBUG request body '' 2020-06-17T10:09:12Z DEBUG response status 200 2020-06-17T10:09:12Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=A2F71E956AC87259E588500A71025282; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:12Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:12Z DEBUG request body 'desc=This certificate profile is for enrolling router certificates.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=flatFileAuth\nname=One Time Pin Router Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\nprofileId=caRouterCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:12Z DEBUG response status 409 2020-06-17T10:09:12Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:12Z DEBUG Error migrating 'caRouterCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:12Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caRouterCert?action=enable 2020-06-17T10:09:12Z DEBUG request body '' 2020-06-17T10:09:12Z DEBUG response status 409 2020-06-17T10:09:12Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:12Z DEBUG Failed to enable profile 'caRouterCert' (it is probably already enabled) 2020-06-17T10:09:12Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:12Z DEBUG request body '' 2020-06-17T10:09:12Z DEBUG response status 204 2020-06-17T10:09:12Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=4A2451E89C82803BB718EC9D3B557B27; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'' 2020-06-17T10:09:12Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:12Z DEBUG request body '' 2020-06-17T10:09:12Z DEBUG response status 200 2020-06-17T10:09:12Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=812D1FA80D05E44B9D981997F2D9C7AA; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:12Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:12Z DEBUG request body 'desc=This certificate profile is for enrolling server certificates.\nvisible=true\nenable=true\nenableBy=admin\nauth.class_id=\nname=Manual Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=.*CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name Extension\nprofileId=caServerCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:12Z DEBUG response status 409 2020-06-17T10:09:12Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:12Z DEBUG Error migrating 'caServerCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:12Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caServerCert?action=enable 2020-06-17T10:09:12Z DEBUG request body '' 2020-06-17T10:09:12Z DEBUG response status 409 2020-06-17T10:09:12Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:12Z DEBUG Failed to enable profile 'caServerCert' (it is probably already enabled) 2020-06-17T10:09:12Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:12Z DEBUG request body '' 2020-06-17T10:09:12Z DEBUG response status 204 2020-06-17T10:09:12Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=5BB5B77AB06ECECB4808CD75DA0F2AAF; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'' 2020-06-17T10:09:12Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:12Z DEBUG request body '' 2020-06-17T10:09:12Z DEBUG response status 200 2020-06-17T10:09:12Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=31F7E961CBCF40E7E7CC58DA2C865D91; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:12Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:12Z DEBUG request body 'desc=This certificate profile is for enrolling server certificates with ECC keys.\nvisible=true\nenable=true\nenableBy=admin\nauth.class_id=\nname=Manual Server Certificate Enrollment with ECC keys\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=.*CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=-\npolicyset.serverCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name Extension\nprofileId=caECServerCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:12Z DEBUG response status 409 2020-06-17T10:09:12Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:12Z DEBUG Error migrating 'caECServerCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:12Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caECServerCert?action=enable 2020-06-17T10:09:12Z DEBUG request body '' 2020-06-17T10:09:12Z DEBUG response status 409 2020-06-17T10:09:12Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:12Z DEBUG Failed to enable profile 'caECServerCert' (it is probably already enabled) 2020-06-17T10:09:12Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:12Z DEBUG request body '' 2020-06-17T10:09:12Z DEBUG response status 204 2020-06-17T10:09:12Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=A85C1E0B36E85232A00E0E3991C32015; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'' 2020-06-17T10:09:12Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:12Z DEBUG request body '' 2020-06-17T10:09:12Z DEBUG response status 200 2020-06-17T10:09:12Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=97127A9993189799BD4B43FF2C7D328D; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:12Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:12Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:12Z DEBUG request body 'desc=This certificate profile is for enrolling subsystem certificates.\nvisible=true\nenable=true\nenableBy=admin\nauth.class_id=\nname=Manual Subsystem Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\nprofileId=caSubsystemCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:13Z DEBUG response status 409 2020-06-17T10:09:13Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:13Z DEBUG Error migrating 'caSubsystemCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:13Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caSubsystemCert?action=enable 2020-06-17T10:09:13Z DEBUG request body '' 2020-06-17T10:09:13Z DEBUG response status 409 2020-06-17T10:09:13Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:13Z DEBUG Failed to enable profile 'caSubsystemCert' (it is probably already enabled) 2020-06-17T10:09:13Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:13Z DEBUG request body '' 2020-06-17T10:09:13Z DEBUG response status 204 2020-06-17T10:09:13Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=AB95FE06081BA662DD7B0CC22315BE3E; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'' 2020-06-17T10:09:13Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:13Z DEBUG request body '' 2020-06-17T10:09:13Z DEBUG response status 200 2020-06-17T10:09:13Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=9C9F32CDB29C2105DB14F521796C2F0E; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:13Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:13Z DEBUG request body 'desc=This certificate profile is for enrolling subsystem certificates with ECC keys.\nvisible=true\nenable=true\nenableBy=admin\nauth.class_id=\nname=Manual Subsystem Certificate Enrollment with ECC keys\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=-\npolicyset.serverCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\nprofileId=caECSubsystemCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:13Z DEBUG response status 409 2020-06-17T10:09:13Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:13Z DEBUG Error migrating 'caECSubsystemCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:13Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caECSubsystemCert?action=enable 2020-06-17T10:09:13Z DEBUG request body '' 2020-06-17T10:09:13Z DEBUG response status 409 2020-06-17T10:09:13Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:12 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:13Z DEBUG Failed to enable profile 'caECSubsystemCert' (it is probably already enabled) 2020-06-17T10:09:13Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:13Z DEBUG request body '' 2020-06-17T10:09:13Z DEBUG response status 204 2020-06-17T10:09:13Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=DD740796F1BE8455BDE5969B550A583D; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'' 2020-06-17T10:09:13Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:13Z DEBUG request body '' 2020-06-17T10:09:13Z DEBUG response status 200 2020-06-17T10:09:13Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=803BD3754C09326DC19260796C2EBEFD; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:13Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:13Z DEBUG request body 'desc=This certificate profile is for enrolling other certificates.\nvisible=true\nenable=true\nenableBy=admin\nauth.class_id=\nname=Other Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=otherCertSet\npolicyset.otherCertSet.list=1,2,3,4,5,6,7,8\npolicyset.otherCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.otherCertSet.1.constraint.name=Subject Name Constraint\npolicyset.otherCertSet.1.constraint.params.pattern=CN=.*\npolicyset.otherCertSet.1.constraint.params.accept=true\npolicyset.otherCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.otherCertSet.1.default.name=Subject Name Default\npolicyset.otherCertSet.1.default.params.name=\npolicyset.otherCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.otherCertSet.2.constraint.name=Validity Constraint\npolicyset.otherCertSet.2.constraint.params.range=720\npolicyset.otherCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.otherCertSet.2.constraint.params.notAfterCheck=false\npolicyset.otherCertSet.2.default.class_id=validityDefaultImpl\npolicyset.otherCertSet.2.default.name=Validity Default\npolicyset.otherCertSet.2.default.params.range=720\npolicyset.otherCertSet.2.default.params.startTime=0\npolicyset.otherCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.otherCertSet.3.constraint.name=Key Constraint\npolicyset.otherCertSet.3.constraint.params.keyType=-\npolicyset.otherCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.otherCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.otherCertSet.3.default.name=Key Default\npolicyset.otherCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.otherCertSet.4.constraint.name=No Constraint\npolicyset.otherCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.otherCertSet.4.default.name=Authority Key Identifier Default\npolicyset.otherCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.otherCertSet.5.constraint.name=No Constraint\npolicyset.otherCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.otherCertSet.5.default.name=AIA Extension Default\npolicyset.otherCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.otherCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.otherCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.otherCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.otherCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.otherCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.otherCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.otherCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.otherCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.otherCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.otherCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.otherCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.otherCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.otherCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.otherCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.otherCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.otherCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.otherCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.otherCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.otherCertSet.6.default.name=Key Usage Default\npolicyset.otherCertSet.6.default.params.keyUsageCritical=true\npolicyset.otherCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.otherCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.otherCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.otherCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.otherCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.otherCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.otherCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.otherCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.otherCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.otherCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.otherCertSet.7.constraint.name=No Constraint\npolicyset.otherCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.otherCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.otherCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.otherCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.otherCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.otherCertSet.8.constraint.name=No Constraint\npolicyset.otherCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.otherCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.otherCertSet.8.default.name=Signing Alg\npolicyset.otherCertSet.8.default.params.signingAlg=-\nprofileId=caOtherCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:13Z DEBUG response status 409 2020-06-17T10:09:13Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:13Z DEBUG Error migrating 'caOtherCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:13Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caOtherCert?action=enable 2020-06-17T10:09:13Z DEBUG request body '' 2020-06-17T10:09:13Z DEBUG response status 409 2020-06-17T10:09:13Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:13Z DEBUG Failed to enable profile 'caOtherCert' (it is probably already enabled) 2020-06-17T10:09:13Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:13Z DEBUG request body '' 2020-06-17T10:09:13Z DEBUG response status 204 2020-06-17T10:09:13Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=B1EC5EC41C98B9F235632FA0A405FE55; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'' 2020-06-17T10:09:13Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:13Z DEBUG request body '' 2020-06-17T10:09:13Z DEBUG response status 200 2020-06-17T10:09:13Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=F16A405648A8AFE1E9E30F44CA1441F8; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:13Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:13Z DEBUG request body 'desc=This certificate profile is for enrolling Certificate Authority certificates.\nvisible=true\nenable=true\nenableBy=admin\nauth.class_id=\nname=Manual Certificate Manager Signing Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=caCertSet\npolicyset.caCertSet.list=1,2,3,4,5,6,8,9,10\npolicyset.caCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.caCertSet.1.constraint.name=Subject Name Constraint\npolicyset.caCertSet.1.constraint.params.pattern=CN=.*\npolicyset.caCertSet.1.constraint.params.accept=true\npolicyset.caCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.caCertSet.1.default.name=Subject Name Default\npolicyset.caCertSet.1.default.params.name=\npolicyset.caCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.caCertSet.2.constraint.name=Validity Constraint\npolicyset.caCertSet.2.constraint.params.range=7305\npolicyset.caCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.caCertSet.2.constraint.params.notAfterCheck=false\npolicyset.caCertSet.2.default.class_id=caValidityDefaultImpl\npolicyset.caCertSet.2.default.name=CA Certificate Validity Default\npolicyset.caCertSet.2.default.params.range=7305\npolicyset.caCertSet.2.default.params.startTime=0\npolicyset.caCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.caCertSet.3.constraint.name=Key Constraint\npolicyset.caCertSet.3.constraint.params.keyType=-\npolicyset.caCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.caCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.caCertSet.3.default.name=Key Default\npolicyset.caCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.4.constraint.name=No Constraint\npolicyset.caCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.caCertSet.4.default.name=Authority Key Identifier Default\npolicyset.caCertSet.5.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.caCertSet.5.constraint.name=Basic Constraint Extension Constraint\npolicyset.caCertSet.5.constraint.params.basicConstraintsCritical=true\npolicyset.caCertSet.5.constraint.params.basicConstraintsIsCA=true\npolicyset.caCertSet.5.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.caCertSet.5.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.caCertSet.5.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.caCertSet.5.default.name=Basic Constraints Extension Default\npolicyset.caCertSet.5.default.params.basicConstraintsCritical=true\npolicyset.caCertSet.5.default.params.basicConstraintsIsCA=true\npolicyset.caCertSet.5.default.params.basicConstraintsPathLen=-1\npolicyset.caCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.caCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.caCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.caCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.caCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.caCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyCertSign=true\npolicyset.caCertSet.6.constraint.params.keyUsageCrlSign=true\npolicyset.caCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.caCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.caCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.caCertSet.6.default.name=Key Usage Default\npolicyset.caCertSet.6.default.params.keyUsageCritical=true\npolicyset.caCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.caCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.caCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.caCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.caCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.caCertSet.6.default.params.keyUsageKeyCertSign=true\npolicyset.caCertSet.6.default.params.keyUsageCrlSign=true\npolicyset.caCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.caCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.caCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.8.constraint.name=No Constraint\npolicyset.caCertSet.8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.caCertSet.8.default.name=Subject Key Identifier Extension Default\npolicyset.caCertSet.8.default.params.critical=false\npolicyset.caCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.caCertSet.9.constraint.name=No Constraint\npolicyset.caCertSet.9.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.caCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.caCertSet.9.default.name=Signing Alg\npolicyset.caCertSet.9.default.params.signingAlg=-\npolicyset.caCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.10.constraint.name=No Constraint\npolicyset.caCertSet.10.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.caCertSet.10.default.name=AIA Extension Default\npolicyset.caCertSet.10.default.params.authInfoAccessADEnable_0=true\npolicyset.caCertSet.10.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.caCertSet.10.default.params.authInfoAccessADLocation_0=\npolicyset.caCertSet.10.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.caCertSet.10.default.params.authInfoAccessCritical=false\npolicyset.caCertSet.10.default.params.authInfoAccessNumADs=1\nprofileId=caCACert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:13Z DEBUG response status 409 2020-06-17T10:09:13Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:13Z DEBUG Error migrating 'caCACert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:13Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caCACert?action=enable 2020-06-17T10:09:13Z DEBUG request body '' 2020-06-17T10:09:13Z DEBUG response status 409 2020-06-17T10:09:13Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:13Z DEBUG Failed to enable profile 'caCACert' (it is probably already enabled) 2020-06-17T10:09:13Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:13Z DEBUG request body '' 2020-06-17T10:09:13Z DEBUG response status 204 2020-06-17T10:09:13Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=59E82C51DECF0AB1D192490A168A6600; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'' 2020-06-17T10:09:13Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:13Z DEBUG request body '' 2020-06-17T10:09:13Z DEBUG response status 200 2020-06-17T10:09:13Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=77866AED7F35A04E47F0405565AEF09F; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:13Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:13Z DEBUG request body 'desc=This certificate profile is for enrolling Certificate Authority certificates using CMC.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=Certificate Manager Signing Certificate Enrollment using CMC\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=caCertSet\npolicyset.caCertSet.list=1,2,3,4,5,6,8,9,10\npolicyset.caCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.caCertSet.1.constraint.name=Subject Name Constraint\npolicyset.caCertSet.1.constraint.params.pattern=CN=.*\npolicyset.caCertSet.1.constraint.params.accept=true\npolicyset.caCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.caCertSet.1.default.name=Subject Name Default\npolicyset.caCertSet.1.default.params.name=\npolicyset.caCertSet.2.constraint.class_id=caValidityConstraintImpl\npolicyset.caCertSet.2.constraint.name=CA Validity Constraint\npolicyset.caCertSet.2.constraint.params.range=7305\npolicyset.caCertSet.2.default.class_id=caValidityDefaultImpl\npolicyset.caCertSet.2.default.name=CA Certificate Validity Default\npolicyset.caCertSet.2.default.params.range=7305\npolicyset.caCertSet.2.default.params.startTime=0\npolicyset.caCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.caCertSet.3.constraint.name=Key Constraint\npolicyset.caCertSet.3.constraint.params.keyType=-\npolicyset.caCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.caCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.caCertSet.3.default.name=Key Default\npolicyset.caCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.4.constraint.name=No Constraint\npolicyset.caCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.caCertSet.4.default.name=Authority Key Identifier Default\npolicyset.caCertSet.5.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.caCertSet.5.constraint.name=Basic Constraint Extension Constraint\npolicyset.caCertSet.5.constraint.params.basicConstraintsCritical=true\npolicyset.caCertSet.5.constraint.params.basicConstraintsIsCA=true\npolicyset.caCertSet.5.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.caCertSet.5.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.caCertSet.5.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.caCertSet.5.default.name=Basic Constraints Extension Default\npolicyset.caCertSet.5.default.params.basicConstraintsCritical=true\npolicyset.caCertSet.5.default.params.basicConstraintsIsCA=true\npolicyset.caCertSet.5.default.params.basicConstraintsPathLen=-1\npolicyset.caCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.caCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.caCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.caCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.caCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.caCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyCertSign=true\npolicyset.caCertSet.6.constraint.params.keyUsageCrlSign=true\npolicyset.caCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.caCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.caCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.caCertSet.6.default.name=Key Usage Default\npolicyset.caCertSet.6.default.params.keyUsageCritical=true\npolicyset.caCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.caCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.caCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.caCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.caCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.caCertSet.6.default.params.keyUsageKeyCertSign=true\npolicyset.caCertSet.6.default.params.keyUsageCrlSign=true\npolicyset.caCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.caCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.caCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.8.constraint.name=No Constraint\npolicyset.caCertSet.8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.caCertSet.8.default.name=Subject Key Identifier Extension Default\npolicyset.caCertSet.8.default.params.critical=false\npolicyset.caCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.caCertSet.9.constraint.name=No Constraint\npolicyset.caCertSet.9.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.caCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.caCertSet.9.default.name=Signing Alg\npolicyset.caCertSet.9.default.params.signingAlg=-\npolicyset.caCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.10.constraint.name=No Constraint\npolicyset.caCertSet.10.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.caCertSet.10.default.name=AIA Extension Default\npolicyset.caCertSet.10.default.params.authInfoAccessADEnable_0=true\npolicyset.caCertSet.10.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.caCertSet.10.default.params.authInfoAccessADLocation_0=\npolicyset.caCertSet.10.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.caCertSet.10.default.params.authInfoAccessCritical=false\npolicyset.caCertSet.10.default.params.authInfoAccessNumADs=1\nprofileId=caCMCcaCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:13Z DEBUG response status 409 2020-06-17T10:09:13Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:13Z DEBUG Error migrating 'caCMCcaCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:13Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caCMCcaCert?action=enable 2020-06-17T10:09:13Z DEBUG request body '' 2020-06-17T10:09:13Z DEBUG response status 409 2020-06-17T10:09:13Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:13Z DEBUG Failed to enable profile 'caCMCcaCert' (it is probably already enabled) 2020-06-17T10:09:13Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:13Z DEBUG request body '' 2020-06-17T10:09:13Z DEBUG response status 204 2020-06-17T10:09:13Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=1F8BD0954A96EB02B021D1F97DFE874E; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'' 2020-06-17T10:09:13Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:13Z DEBUG request body '' 2020-06-17T10:09:13Z DEBUG response status 200 2020-06-17T10:09:13Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=07EDAA87A0A83C19F130C26601DAB82D; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:13Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:13Z DEBUG request body 'desc=This certificate profile is for enrolling Cross Signed Certificate Authority certificates.\nvisible=false\nenable=false\nenableBy=admin\nauth.class_id=\nname=Manual Cross Signed Certificate Manager Signing Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=caCertSet\npolicyset.caCertSet.list=1,2,3,4,5,6,8,9,10\npolicyset.caCertSet.1.constraint.class_id=userSubjectNameConstraintImpl\npolicyset.caCertSet.1.constraint.name=User Subject Name Constraint\npolicyset.caCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.caCertSet.1.default.name=User Supplied Subject Name Default\npolicyset.caCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.caCertSet.2.constraint.name=Validity Constraint\npolicyset.caCertSet.2.constraint.params.range=7305\npolicyset.caCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.caCertSet.2.constraint.params.notAfterCheck=false\npolicyset.caCertSet.2.default.class_id=caValidityDefaultImpl\npolicyset.caCertSet.2.default.name=CA Certificate Validity Default\npolicyset.caCertSet.2.default.params.range=7305\npolicyset.caCertSet.2.default.params.startTime=0\npolicyset.caCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.caCertSet.3.constraint.name=Key Constraint\npolicyset.caCertSet.3.constraint.params.keyType=-\npolicyset.caCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.caCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.caCertSet.3.default.name=Key Default\npolicyset.caCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.4.constraint.name=No Constraint\npolicyset.caCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.caCertSet.4.default.name=Authority Key Identifier Default\npolicyset.caCertSet.5.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.caCertSet.5.constraint.name=Basic Constraint Extension Constraint\npolicyset.caCertSet.5.constraint.params.basicConstraintsCritical=true\npolicyset.caCertSet.5.constraint.params.basicConstraintsIsCA=true\npolicyset.caCertSet.5.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.caCertSet.5.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.caCertSet.5.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.caCertSet.5.default.name=Basic Constraints Extension Default\npolicyset.caCertSet.5.default.params.basicConstraintsCritical=true\npolicyset.caCertSet.5.default.params.basicConstraintsIsCA=true\npolicyset.caCertSet.5.default.params.basicConstraintsPathLen=-1\npolicyset.caCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.caCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.caCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.caCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.caCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.caCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyCertSign=true\npolicyset.caCertSet.6.constraint.params.keyUsageCrlSign=true\npolicyset.caCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.caCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.caCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.caCertSet.6.default.name=Key Usage Default\npolicyset.caCertSet.6.default.params.keyUsageCritical=true\npolicyset.caCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.caCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.caCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.caCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.caCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.caCertSet.6.default.params.keyUsageKeyCertSign=true\npolicyset.caCertSet.6.default.params.keyUsageCrlSign=true\npolicyset.caCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.caCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.caCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.8.constraint.name=No Constraint\npolicyset.caCertSet.8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.caCertSet.8.default.name=Subject Key Identifier Extension Default\npolicyset.caCertSet.8.default.params.critical=false\npolicyset.caCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.caCertSet.9.constraint.name=No Constraint\npolicyset.caCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.caCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.caCertSet.9.default.name=Signing Alg\npolicyset.caCertSet.9.default.params.signingAlg=-\npolicyset.caCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.10.constraint.name=No Constraint\npolicyset.caCertSet.10.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.caCertSet.10.default.name=AIA Extension Default\npolicyset.caCertSet.10.default.params.authInfoAccessADEnable_0=true\npolicyset.caCertSet.10.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.caCertSet.10.default.params.authInfoAccessADLocation_0=\npolicyset.caCertSet.10.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.caCertSet.10.default.params.authInfoAccessCritical=false\npolicyset.caCertSet.10.default.params.authInfoAccessNumADs=1\nprofileId=caCrossSignedCACert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:13Z DEBUG response status 409 2020-06-17T10:09:13Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:13Z DEBUG Error migrating 'caCrossSignedCACert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:13Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caCrossSignedCACert?action=enable 2020-06-17T10:09:13Z DEBUG request body '' 2020-06-17T10:09:13Z DEBUG response status 204 2020-06-17T10:09:13Z DEBUG response headers Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'' 2020-06-17T10:09:13Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:13Z DEBUG request body '' 2020-06-17T10:09:13Z DEBUG response status 204 2020-06-17T10:09:13Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=A5C3BAB6C527B0C73C87800C409DB895; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:13Z DEBUG response body (decoded): b'' 2020-06-17T10:09:14Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:14Z DEBUG request body '' 2020-06-17T10:09:14Z DEBUG response status 200 2020-06-17T10:09:14Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=3F2CCB1271882116C63706C5D50B4E7F; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:14Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:14Z DEBUG request body 'desc=This certificate profile is for enrolling Security Domain Certificate Authority certificates.\nvisible=true\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Manual Security Domain Certificate Authority Signing Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=caCertSet\npolicyset.caCertSet.list=1,2,3,4,5,6,8,9,10\npolicyset.caCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.caCertSet.1.constraint.name=Subject Name Constraint\npolicyset.caCertSet.1.constraint.params.pattern=CN=.*\npolicyset.caCertSet.1.constraint.params.accept=true\npolicyset.caCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.caCertSet.1.default.name=Subject Name Default\npolicyset.caCertSet.1.default.params.name=\npolicyset.caCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.caCertSet.2.constraint.name=Validity Constraint\npolicyset.caCertSet.2.constraint.params.range=720\npolicyset.caCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.caCertSet.2.constraint.params.notAfterCheck=false\npolicyset.caCertSet.2.default.class_id=validityDefaultImpl\npolicyset.caCertSet.2.default.name=Validity Default\npolicyset.caCertSet.2.default.params.range=720\npolicyset.caCertSet.2.default.params.startTime=0\npolicyset.caCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.caCertSet.3.constraint.name=Key Constraint\npolicyset.caCertSet.3.constraint.params.keyType=-\npolicyset.caCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.caCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.caCertSet.3.default.name=Key Default\npolicyset.caCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.4.constraint.name=No Constraint\npolicyset.caCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.caCertSet.4.default.name=Authority Key Identifier Default\npolicyset.caCertSet.5.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.caCertSet.5.constraint.name=Basic Constraint Extension Constraint\npolicyset.caCertSet.5.constraint.params.basicConstraintsCritical=true\npolicyset.caCertSet.5.constraint.params.basicConstraintsIsCA=true\npolicyset.caCertSet.5.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.caCertSet.5.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.caCertSet.5.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.caCertSet.5.default.name=Basic Constraints Extension Default\npolicyset.caCertSet.5.default.params.basicConstraintsCritical=true\npolicyset.caCertSet.5.default.params.basicConstraintsIsCA=true\npolicyset.caCertSet.5.default.params.basicConstraintsPathLen=-1\npolicyset.caCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.caCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.caCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.caCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.caCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.caCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyCertSign=true\npolicyset.caCertSet.6.constraint.params.keyUsageCrlSign=true\npolicyset.caCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.caCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.caCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.caCertSet.6.default.name=Key Usage Default\npolicyset.caCertSet.6.default.params.keyUsageCritical=true\npolicyset.caCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.caCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.caCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.caCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.caCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.caCertSet.6.default.params.keyUsageKeyCertSign=true\npolicyset.caCertSet.6.default.params.keyUsageCrlSign=true\npolicyset.caCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.caCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.caCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.8.constraint.name=No Constraint\npolicyset.caCertSet.8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.caCertSet.8.default.name=Subject Key Identifier Extension Default\npolicyset.caCertSet.8.default.params.critical=false\npolicyset.caCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.caCertSet.9.constraint.name=No Constraint\npolicyset.caCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.caCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.caCertSet.9.default.name=Signing Alg\npolicyset.caCertSet.9.default.params.signingAlg=-\npolicyset.caCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.10.constraint.name=No Constraint\npolicyset.caCertSet.10.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.caCertSet.10.default.name=AIA Extension Default\npolicyset.caCertSet.10.default.params.authInfoAccessADEnable_0=true\npolicyset.caCertSet.10.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.caCertSet.10.default.params.authInfoAccessADLocation_0=\npolicyset.caCertSet.10.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.caCertSet.10.default.params.authInfoAccessCritical=false\npolicyset.caCertSet.10.default.params.authInfoAccessNumADs=1\nprofileId=caInstallCACert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:14Z DEBUG response status 409 2020-06-17T10:09:14Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:14Z DEBUG Error migrating 'caInstallCACert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:14Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caInstallCACert?action=enable 2020-06-17T10:09:14Z DEBUG request body '' 2020-06-17T10:09:14Z DEBUG response status 409 2020-06-17T10:09:14Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:14Z DEBUG Failed to enable profile 'caInstallCACert' (it is probably already enabled) 2020-06-17T10:09:14Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:14Z DEBUG request body '' 2020-06-17T10:09:14Z DEBUG response status 204 2020-06-17T10:09:14Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=C56D7993F129884A70B2D25CB6B73C21; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'' 2020-06-17T10:09:14Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:14Z DEBUG request body '' 2020-06-17T10:09:14Z DEBUG response status 200 2020-06-17T10:09:14Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=770CDA19193EDE46F794D397AA7BBBD3; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:14Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:14Z DEBUG request body 'desc=This certificate profile is for enrolling Registration Manager certificates.\nvisible=false\nenable=false\nenableBy=admin\nauth.class_id=\nname=Manual Registration Manager Signing Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=raCertSet\npolicyset.raCertSet.list=1,2,3,4,5,6,7,8\npolicyset.raCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.raCertSet.1.constraint.name=Subject Name Constraint\npolicyset.raCertSet.1.constraint.params.pattern=CN=.*\npolicyset.raCertSet.1.constraint.params.accept=true\npolicyset.raCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.raCertSet.1.default.name=Subject Name Default\npolicyset.raCertSet.1.default.params.name=\npolicyset.raCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.raCertSet.2.constraint.name=Validity Constraint\npolicyset.raCertSet.2.constraint.params.range=720\npolicyset.raCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.raCertSet.2.constraint.params.notAfterCheck=false\npolicyset.raCertSet.2.default.class_id=validityDefaultImpl\npolicyset.raCertSet.2.default.name=Validity Default\npolicyset.raCertSet.2.default.params.range=720\npolicyset.raCertSet.2.default.params.startTime=0\npolicyset.raCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.raCertSet.3.constraint.name=Key Constraint\npolicyset.raCertSet.3.constraint.params.keyType=RSA\npolicyset.raCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.raCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.raCertSet.3.default.name=Key Default\npolicyset.raCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.raCertSet.4.constraint.name=No Constraint\npolicyset.raCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.raCertSet.4.default.name=Authority Key Identifier Default\npolicyset.raCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.raCertSet.5.constraint.name=No Constraint\npolicyset.raCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.raCertSet.5.default.name=AIA Extension Default\npolicyset.raCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.raCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.raCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.raCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.raCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.raCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.raCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.raCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.raCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.raCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.raCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.raCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.raCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.raCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.raCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.raCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.raCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.raCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.raCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.raCertSet.6.default.name=Key Usage Default\npolicyset.raCertSet.6.default.params.keyUsageCritical=true\npolicyset.raCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.raCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.raCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.raCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.raCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.raCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.raCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.raCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.raCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.raCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.raCertSet.7.constraint.name=No Constraint\npolicyset.raCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.raCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.raCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.raCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.raCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.raCertSet.8.constraint.name=No Constraint\npolicyset.raCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.raCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.raCertSet.8.default.name=Signing Alg\npolicyset.raCertSet.8.default.params.signingAlg=-\nprofileId=caRACert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:14Z DEBUG response status 409 2020-06-17T10:09:14Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:13 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:14Z DEBUG Error migrating 'caRACert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:14Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caRACert?action=enable 2020-06-17T10:09:14Z DEBUG request body '' 2020-06-17T10:09:14Z DEBUG response status 204 2020-06-17T10:09:14Z DEBUG response headers Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'' 2020-06-17T10:09:14Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:14Z DEBUG request body '' 2020-06-17T10:09:14Z DEBUG response status 204 2020-06-17T10:09:14Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=5987648E4944AF50AB145DD9140DEDBF; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'' 2020-06-17T10:09:14Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:14Z DEBUG request body '' 2020-06-17T10:09:14Z DEBUG response status 200 2020-06-17T10:09:14Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=E3F0A6A49B1E0DC4246195C4A7C87FE1; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:14Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:14Z DEBUG request body 'desc=This certificate profile is for enrolling OCSP Manager certificates.\nvisible=true\nenable=true\nenableBy=admin\nauth.class_id=\nname=Manual OCSP Manager Signing Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=ocspCertSet\npolicyset.ocspCertSet.list=1,2,3,4,5,6,8,9\npolicyset.ocspCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.ocspCertSet.1.constraint.name=Subject Name Constraint\npolicyset.ocspCertSet.1.constraint.params.pattern=CN=.*\npolicyset.ocspCertSet.1.constraint.params.accept=true\npolicyset.ocspCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.ocspCertSet.1.default.name=Subject Name Default\npolicyset.ocspCertSet.1.default.params.name=\npolicyset.ocspCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.ocspCertSet.2.constraint.name=Validity Constraint\npolicyset.ocspCertSet.2.constraint.params.range=720\npolicyset.ocspCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.ocspCertSet.2.constraint.params.notAfterCheck=false\npolicyset.ocspCertSet.2.default.class_id=validityDefaultImpl\npolicyset.ocspCertSet.2.default.name=Validity Default\npolicyset.ocspCertSet.2.default.params.range=720\npolicyset.ocspCertSet.2.default.params.startTime=0\npolicyset.ocspCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.ocspCertSet.3.constraint.name=Key Constraint\npolicyset.ocspCertSet.3.constraint.params.keyType=-\npolicyset.ocspCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.ocspCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.ocspCertSet.3.default.name=Key Default\npolicyset.ocspCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.ocspCertSet.4.constraint.name=No Constraint\npolicyset.ocspCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.ocspCertSet.4.default.name=Authority Key Identifier Default\npolicyset.ocspCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.ocspCertSet.5.constraint.name=No Constraint\npolicyset.ocspCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.ocspCertSet.5.default.name=AIA Extension Default\npolicyset.ocspCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.ocspCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.ocspCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.ocspCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.ocspCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.ocspCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.ocspCertSet.6.constraint.class_id=extendedKeyUsageExtConstraintImpl\npolicyset.ocspCertSet.6.constraint.name=Extended Key Usage Extension\npolicyset.ocspCertSet.6.constraint.params.exKeyUsageCritical=false\npolicyset.ocspCertSet.6.constraint.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.9\npolicyset.ocspCertSet.6.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.ocspCertSet.6.default.name=Extended Key Usage Default\npolicyset.ocspCertSet.6.default.params.exKeyUsageCritical=false\npolicyset.ocspCertSet.6.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.9\npolicyset.ocspCertSet.8.constraint.class_id=extensionConstraintImpl\npolicyset.ocspCertSet.8.constraint.name=No Constraint\npolicyset.ocspCertSet.8.constraint.params.extCritical=false\npolicyset.ocspCertSet.8.constraint.params.extOID=1.3.6.1.5.5.7.48.1.5\npolicyset.ocspCertSet.8.default.class_id=ocspNoCheckExtDefaultImpl\npolicyset.ocspCertSet.8.default.name=OCSP No Check Extension\npolicyset.ocspCertSet.8.default.params.ocspNoCheckCritical=false\npolicyset.ocspCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.ocspCertSet.9.constraint.name=No Constraint\npolicyset.ocspCertSet.9.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.ocspCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.ocspCertSet.9.default.name=Signing Alg\npolicyset.ocspCertSet.9.default.params.signingAlg=-\nprofileId=caOCSPCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:14Z DEBUG response status 409 2020-06-17T10:09:14Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:14Z DEBUG Error migrating 'caOCSPCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:14Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caOCSPCert?action=enable 2020-06-17T10:09:14Z DEBUG request body '' 2020-06-17T10:09:14Z DEBUG response status 409 2020-06-17T10:09:14Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:14Z DEBUG Failed to enable profile 'caOCSPCert' (it is probably already enabled) 2020-06-17T10:09:14Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:14Z DEBUG request body '' 2020-06-17T10:09:14Z DEBUG response status 204 2020-06-17T10:09:14Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=7E84894195E8B4661DA30944F1EF2A4F; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'' 2020-06-17T10:09:14Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:14Z DEBUG request body '' 2020-06-17T10:09:14Z DEBUG response status 200 2020-06-17T10:09:14Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=B577C4811557329B402DB35633C5A29E; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:14Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:14Z DEBUG request body 'desc=This certificate profile is for enrolling Data Recovery Manager storage certificates.\nvisible=true\nenable=true\nenableBy=admin\nauth.class.id=\nname=Manual Data Recovery Manager Storage Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=drmStorageCertSet\npolicyset.drmStorageCertSet.list=1,2,3,4,5,6,9\npolicyset.drmStorageCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.drmStorageCertSet.1.constraint.name=Subject Name Constraint\npolicyset.drmStorageCertSet.1.constraint.params.pattern=CN=.*\npolicyset.drmStorageCertSet.1.constraint.params.accept=true\npolicyset.drmStorageCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.drmStorageCertSet.1.default.name=Subject Name Default\npolicyset.drmStorageCertSet.1.default.params.name=\npolicyset.drmStorageCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.drmStorageCertSet.2.constraint.name=Validity Constraint\npolicyset.drmStorageCertSet.2.constraint.params.range=720\npolicyset.drmStorageCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.drmStorageCertSet.2.constraint.params.notAfterCheck=false\npolicyset.drmStorageCertSet.2.default.class_id=validityDefaultImpl\npolicyset.drmStorageCertSet.2.default.name=Validity Default\npolicyset.drmStorageCertSet.2.default.params.range=720\npolicyset.drmStorageCertSet.2.default.params.startTime=0\npolicyset.drmStorageCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.drmStorageCertSet.3.constraint.name=Key Constraint\npolicyset.drmStorageCertSet.3.constraint.params.keyType=RSA\npolicyset.drmStorageCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.drmStorageCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.drmStorageCertSet.3.default.name=Key Default\npolicyset.drmStorageCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.drmStorageCertSet.4.constraint.name=No Constraint\npolicyset.drmStorageCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.drmStorageCertSet.4.default.name=Authority Key Identifier Default\npolicyset.drmStorageCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.drmStorageCertSet.5.constraint.name=No Constraint\npolicyset.drmStorageCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.drmStorageCertSet.5.default.name=AIA Extension Default\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.drmStorageCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.drmStorageCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.drmStorageCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.drmStorageCertSet.6.default.name=Key Usage Default\npolicyset.drmStorageCertSet.6.default.params.keyUsageCritical=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.drmStorageCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.drmStorageCertSet.9.constraint.name=No Constraint\npolicyset.drmStorageCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.drmStorageCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.drmStorageCertSet.9.default.name=Signing Alg\npolicyset.drmStorageCertSet.9.default.params.signingAlg=-\nprofileId=caStorageCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:14Z DEBUG response status 409 2020-06-17T10:09:14Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:14Z DEBUG Error migrating 'caStorageCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:14Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caStorageCert?action=enable 2020-06-17T10:09:14Z DEBUG request body '' 2020-06-17T10:09:14Z DEBUG response status 409 2020-06-17T10:09:14Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:14Z DEBUG Failed to enable profile 'caStorageCert' (it is probably already enabled) 2020-06-17T10:09:14Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:14Z DEBUG request body '' 2020-06-17T10:09:14Z DEBUG response status 204 2020-06-17T10:09:14Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=E805C40A7FDBFFB56FE956AB27736A86; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'' 2020-06-17T10:09:14Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:14Z DEBUG request body '' 2020-06-17T10:09:14Z DEBUG response status 200 2020-06-17T10:09:14Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=5628D97F1DB732113E98C8C3FF3B2F5C; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:14Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:14Z DEBUG request body 'desc=This certificate profile is for enrolling Data Recovery Manager transport certificates.\nvisible=true\nenable=true\nenableBy=admin\nauth.class_id=\nname=Manual Data Recovery Manager Transport Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=transportCertSet\npolicyset.transportCertSet.list=1,2,3,4,5,6,7,8\npolicyset.transportCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.transportCertSet.1.constraint.name=Subject Name Constraint\npolicyset.transportCertSet.1.constraint.params.pattern=CN=.*\npolicyset.transportCertSet.1.constraint.params.accept=true\npolicyset.transportCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.transportCertSet.1.default.name=Subject Name Default\npolicyset.transportCertSet.1.default.params.name=\npolicyset.transportCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.transportCertSet.2.constraint.name=Validity Constraint\npolicyset.transportCertSet.2.constraint.params.range=720\npolicyset.transportCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.transportCertSet.2.constraint.params.notAfterCheck=false\npolicyset.transportCertSet.2.default.class_id=validityDefaultImpl\npolicyset.transportCertSet.2.default.name=Validity Default\npolicyset.transportCertSet.2.default.params.range=720\npolicyset.transportCertSet.2.default.params.startTime=0\npolicyset.transportCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.transportCertSet.3.constraint.name=Key Constraint\npolicyset.transportCertSet.3.constraint.params.keyType=RSA\npolicyset.transportCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.transportCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.transportCertSet.3.default.name=Key Default\npolicyset.transportCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.transportCertSet.4.constraint.name=No Constraint\npolicyset.transportCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.transportCertSet.4.default.name=Authority Key Identifier Default\npolicyset.transportCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.transportCertSet.5.constraint.name=No Constraint\npolicyset.transportCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.transportCertSet.5.default.name=AIA Extension Default\npolicyset.transportCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.transportCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.transportCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.transportCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.transportCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.transportCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.transportCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.transportCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.transportCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.transportCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.transportCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.transportCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.transportCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.transportCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.transportCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.transportCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.transportCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.transportCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.transportCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.transportCertSet.6.default.name=Key Usage Default\npolicyset.transportCertSet.6.default.params.keyUsageCritical=true\npolicyset.transportCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.transportCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.transportCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.transportCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.transportCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.transportCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.transportCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.transportCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.transportCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.transportCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.transportCertSet.7.constraint.name=No Constraint\npolicyset.transportCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.transportCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.transportCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.transportCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.transportCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.transportCertSet.8.constraint.name=No Constraint\npolicyset.transportCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.transportCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.transportCertSet.8.default.name=Signing Alg\npolicyset.transportCertSet.8.default.params.signingAlg=-\nprofileId=caTransportCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:14Z DEBUG response status 409 2020-06-17T10:09:14Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:14Z DEBUG Error migrating 'caTransportCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:14Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caTransportCert?action=enable 2020-06-17T10:09:14Z DEBUG request body '' 2020-06-17T10:09:14Z DEBUG response status 409 2020-06-17T10:09:14Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:14Z DEBUG Failed to enable profile 'caTransportCert' (it is probably already enabled) 2020-06-17T10:09:14Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:14Z DEBUG request body '' 2020-06-17T10:09:14Z DEBUG response status 204 2020-06-17T10:09:14Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=FFF7498CF390B3FE3B1BF3340989A4DD; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'' 2020-06-17T10:09:14Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:14Z DEBUG request body '' 2020-06-17T10:09:14Z DEBUG response status 200 2020-06-17T10:09:14Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=1EE606CC80810CAC4308BCB566110338; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:14Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:14Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates with directory-pin-based authentication.\nvisible=true\nenable=false\nenableBy=admin\nname=Directory-Pin-Authenticated User Dual-Use Certificate Enrollment\nauth.instance_id=PinDirEnrollment\ninput.list=i1\ninput.i1.class_id=keyGenInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=userCertSet\npolicyset.userCertSet.list=1,10,2,3,4,5,6,7,8,9\npolicyset.userCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.userCertSet.1.constraint.name=Subject Name Constraint\npolicyset.userCertSet.1.constraint.params.pattern=(UID|CN)=.*\npolicyset.userCertSet.1.constraint.params.accept=true\npolicyset.userCertSet.1.default.class_id=authTokenSubjectNameDefaultImpl\npolicyset.userCertSet.1.default.name=Subject Name Default\npolicyset.userCertSet.1.default.params.name=\npolicyset.userCertSet.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.userCertSet.10.constraint.name=Renewal Grace Period Constraint\npolicyset.userCertSet.10.constraint.params.renewal.graceBefore=30\npolicyset.userCertSet.10.constraint.params.renewal.graceAfter=30\npolicyset.userCertSet.10.default.class_id=noDefaultImpl\npolicyset.userCertSet.10.default.name=No Default\npolicyset.userCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.userCertSet.2.constraint.name=Validity Constraint\npolicyset.userCertSet.2.constraint.params.range=365\npolicyset.userCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.userCertSet.2.constraint.params.notAfterCheck=false\npolicyset.userCertSet.2.default.class_id=validityDefaultImpl\npolicyset.userCertSet.2.default.name=Validity Default\npolicyset.userCertSet.2.default.params.range=180\npolicyset.userCertSet.2.default.params.startTime=0\npolicyset.userCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.userCertSet.3.constraint.name=Key Constraint\npolicyset.userCertSet.3.constraint.params.keyType=RSA\npolicyset.userCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.userCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.userCertSet.3.default.name=Key Default\npolicyset.userCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.4.constraint.name=No Constraint\npolicyset.userCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.userCertSet.4.default.name=Authority Key Identifier Default\npolicyset.userCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.5.constraint.name=No Constraint\npolicyset.userCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.userCertSet.5.default.name=AIA Extension Default\npolicyset.userCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.userCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.userCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.userCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.userCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.userCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.userCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.userCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.userCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.userCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.userCertSet.6.default.name=Key Usage Default\npolicyset.userCertSet.6.default.params.keyUsageCritical=true\npolicyset.userCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.7.constraint.name=No Constraint\npolicyset.userCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.userCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.userCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.userCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.userCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.8.constraint.name=No Constraint\npolicyset.userCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.userCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.userCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.userCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.userCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.userCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.userCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.userCertSet.9.constraint.name=No Constraint\npolicyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.userCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.userCertSet.9.default.name=Signing Alg\npolicyset.userCertSet.9.default.params.signingAlg=-\nprofileId=caDirPinUserCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:14Z DEBUG response status 409 2020-06-17T10:09:14Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:14Z DEBUG Error migrating 'caDirPinUserCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:14Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caDirPinUserCert?action=enable 2020-06-17T10:09:14Z DEBUG request body '' 2020-06-17T10:09:14Z DEBUG response status 204 2020-06-17T10:09:14Z DEBUG response headers Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:14Z DEBUG response body (decoded): b'' 2020-06-17T10:09:14Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:14Z DEBUG request body '' 2020-06-17T10:09:15Z DEBUG response status 204 2020-06-17T10:09:15Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=8663EEB7F9171211F050C2EA95238206; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'' 2020-06-17T10:09:15Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:15Z DEBUG request body '' 2020-06-17T10:09:15Z DEBUG response status 200 2020-06-17T10:09:15Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=AD92DEA45CA456697620064A3854CC8C; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:15Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:15Z DEBUG request body 'desc=This certificate profile is for enrolling user ECC certificates with directory-pin-based authentication.\nvisible=true\nenable=false\nenableBy=admin\nname=Directory-Pin-Authenticated User Dual-Use ECC Certificate Enrollment\nauth.instance_id=PinDirEnrollment\ninput.list=i1\ninput.i1.class_id=keyGenInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=userCertSet\npolicyset.userCertSet.list=1,10,2,3,4,5,6,7,8,9\npolicyset.userCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.userCertSet.1.constraint.name=Subject Name Constraint\npolicyset.userCertSet.1.constraint.params.pattern=(UID|CN)=.*\npolicyset.userCertSet.1.constraint.params.accept=true\npolicyset.userCertSet.1.default.class_id=authTokenSubjectNameDefaultImpl\npolicyset.userCertSet.1.default.name=Subject Name Default\npolicyset.userCertSet.1.default.params.name=\npolicyset.userCertSet.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.userCertSet.10.constraint.name=Renewal Grace Period Constraint\npolicyset.userCertSet.10.constraint.params.renewal.graceBefore=30\npolicyset.userCertSet.10.constraint.params.renewal.graceAfter=30\npolicyset.userCertSet.10.default.class_id=noDefaultImpl\npolicyset.userCertSet.10.default.name=No Default\npolicyset.userCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.userCertSet.2.constraint.name=Validity Constraint\npolicyset.userCertSet.2.constraint.params.range=365\npolicyset.userCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.userCertSet.2.constraint.params.notAfterCheck=false\npolicyset.userCertSet.2.default.class_id=validityDefaultImpl\npolicyset.userCertSet.2.default.name=Validity Default\npolicyset.userCertSet.2.default.params.range=180\npolicyset.userCertSet.2.default.params.startTime=0\npolicyset.userCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.userCertSet.3.constraint.name=Key Constraint\npolicyset.userCertSet.3.constraint.params.keyType=-\npolicyset.userCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.userCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.userCertSet.3.default.name=Key Default\npolicyset.userCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.4.constraint.name=No Constraint\npolicyset.userCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.userCertSet.4.default.name=Authority Key Identifier Default\npolicyset.userCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.5.constraint.name=No Constraint\npolicyset.userCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.userCertSet.5.default.name=AIA Extension Default\npolicyset.userCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.userCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.userCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.userCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.userCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.userCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.userCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.userCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.userCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.userCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.userCertSet.6.default.name=Key Usage Default\npolicyset.userCertSet.6.default.params.keyUsageCritical=true\npolicyset.userCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.userCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.7.constraint.name=No Constraint\npolicyset.userCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.userCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.userCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.userCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.userCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.8.constraint.name=No Constraint\npolicyset.userCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.userCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.userCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.userCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.userCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.userCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.userCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.userCertSet.9.constraint.name=No Constraint\npolicyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.userCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.userCertSet.9.default.name=Signing Alg\npolicyset.userCertSet.9.default.params.signingAlg=-\nprofileId=caECDirPinUserCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:15Z DEBUG response status 409 2020-06-17T10:09:15Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:15Z DEBUG Error migrating 'caECDirPinUserCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:15Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caECDirPinUserCert?action=enable 2020-06-17T10:09:15Z DEBUG request body '' 2020-06-17T10:09:15Z DEBUG response status 204 2020-06-17T10:09:15Z DEBUG response headers Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'' 2020-06-17T10:09:15Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:15Z DEBUG request body '' 2020-06-17T10:09:15Z DEBUG response status 204 2020-06-17T10:09:15Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=F68E37FA9099424122308789D49DABD5; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'' 2020-06-17T10:09:15Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:15Z DEBUG request body '' 2020-06-17T10:09:15Z DEBUG response status 200 2020-06-17T10:09:15Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=869E0104264E8EEECD07E853E4C57E63; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:15Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:15Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates with directory-based authentication.\nvisible=true\nenable=true\nenableBy=admin\nname=Directory-Authenticated User Dual-Use Certificate Enrollment\nauth.instance_id=UserDirEnrollment\ninput.list=i1\ninput.i1.class_id=keyGenInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=userCertSet\npolicyset.userCertSet.list=1,10,2,3,4,5,6,7,8,9\npolicyset.userCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.userCertSet.1.constraint.name=Subject Name Constraint\npolicyset.userCertSet.1.constraint.params.pattern=(UID|CN)=.*\npolicyset.userCertSet.1.constraint.params.accept=true\npolicyset.userCertSet.1.default.class_id=authTokenSubjectNameDefaultImpl\npolicyset.userCertSet.1.default.name=Subject Name Default\npolicyset.userCertSet.1.default.params.name=\npolicyset.userCertSet.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.userCertSet.10.constraint.name=Renewal Grace Period Constraint\npolicyset.userCertSet.10.constraint.params.renewal.graceBefore=30\npolicyset.userCertSet.10.constraint.params.renewal.graceAfter=30\npolicyset.userCertSet.10.default.class_id=noDefaultImpl\npolicyset.userCertSet.10.default.name=No Default\npolicyset.userCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.userCertSet.2.constraint.name=Validity Constraint\npolicyset.userCertSet.2.constraint.params.range=365\npolicyset.userCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.userCertSet.2.constraint.params.notAfterCheck=false\npolicyset.userCertSet.2.default.class_id=validityDefaultImpl\npolicyset.userCertSet.2.default.name=Validity Default\npolicyset.userCertSet.2.default.params.range=180\npolicyset.userCertSet.2.default.params.startTime=0\npolicyset.userCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.userCertSet.3.constraint.name=Key Constraint\npolicyset.userCertSet.3.constraint.params.keyType=RSA\npolicyset.userCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.userCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.userCertSet.3.default.name=Key Default\npolicyset.userCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.4.constraint.name=No Constraint\npolicyset.userCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.userCertSet.4.default.name=Authority Key Identifier Default\npolicyset.userCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.5.constraint.name=No Constraint\npolicyset.userCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.userCertSet.5.default.name=AIA Extension Default\npolicyset.userCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.userCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.userCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.userCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.userCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.userCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.userCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.userCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.userCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.userCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.userCertSet.6.default.name=Key Usage Default\npolicyset.userCertSet.6.default.params.keyUsageCritical=true\npolicyset.userCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.7.constraint.name=No Constraint\npolicyset.userCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.userCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.userCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.userCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.userCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.8.constraint.name=No Constraint\npolicyset.userCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.userCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.userCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.userCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.userCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.userCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.userCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.userCertSet.9.constraint.name=No Constraint\npolicyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.userCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.userCertSet.9.default.name=Signing Alg\npolicyset.userCertSet.9.default.params.signingAlg=-\nprofileId=caDirUserCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:15Z DEBUG response status 409 2020-06-17T10:09:15Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:14 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:15Z DEBUG Error migrating 'caDirUserCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:15Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caDirUserCert?action=enable 2020-06-17T10:09:15Z DEBUG request body '' 2020-06-17T10:09:15Z DEBUG response status 409 2020-06-17T10:09:15Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:15Z DEBUG Failed to enable profile 'caDirUserCert' (it is probably already enabled) 2020-06-17T10:09:15Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:15Z DEBUG request body '' 2020-06-17T10:09:15Z DEBUG response status 204 2020-06-17T10:09:15Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=E12E5795BB2F7905DFFFF28B2621B18C; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'' 2020-06-17T10:09:15Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:15Z DEBUG request body '' 2020-06-17T10:09:15Z DEBUG response status 200 2020-06-17T10:09:15Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=37D4556E609277945CF8002866376313; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:15Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:15Z DEBUG request body 'desc=This certificate profile is for enrolling user ECC certificates with directory-based authentication.\nvisible=true\nenable=true\nenableBy=admin\nname=Directory-Authenticated User ECC Certificate Enrollment\nauth.instance_id=UserDirEnrollment\ninput.list=i1\ninput.i1.class_id=keyGenInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=userCertSet\npolicyset.userCertSet.list=1,10,2,3,4,5,6,7,8,9\npolicyset.userCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.userCertSet.1.constraint.name=Subject Name Constraint\npolicyset.userCertSet.1.constraint.params.pattern=(UID|CN)=.*\npolicyset.userCertSet.1.constraint.params.accept=true\npolicyset.userCertSet.1.default.class_id=authTokenSubjectNameDefaultImpl\npolicyset.userCertSet.1.default.name=Subject Name Default\npolicyset.userCertSet.1.default.params.name=\npolicyset.userCertSet.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.userCertSet.10.constraint.name=Renewal Grace Period Constraint\npolicyset.userCertSet.10.constraint.params.renewal.graceBefore=30\npolicyset.userCertSet.10.constraint.params.renewal.graceAfter=30\npolicyset.userCertSet.10.default.class_id=noDefaultImpl\npolicyset.userCertSet.10.default.name=No Default\npolicyset.userCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.userCertSet.2.constraint.name=Validity Constraint\npolicyset.userCertSet.2.constraint.params.range=365\npolicyset.userCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.userCertSet.2.constraint.params.notAfterCheck=false\npolicyset.userCertSet.2.default.class_id=validityDefaultImpl\npolicyset.userCertSet.2.default.name=Validity Default\npolicyset.userCertSet.2.default.params.range=180\npolicyset.userCertSet.2.default.params.startTime=0\npolicyset.userCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.userCertSet.3.constraint.name=Key Constraint\npolicyset.userCertSet.3.constraint.params.keyType=EC\npolicyset.userCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.userCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.userCertSet.3.default.name=Key Default\npolicyset.userCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.4.constraint.name=No Constraint\npolicyset.userCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.userCertSet.4.default.name=Authority Key Identifier Default\npolicyset.userCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.5.constraint.name=No Constraint\npolicyset.userCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.userCertSet.5.default.name=AIA Extension Default\npolicyset.userCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.userCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.userCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.userCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.userCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.userCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.userCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.userCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.userCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.userCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.userCertSet.6.default.name=Key Usage Default\npolicyset.userCertSet.6.default.params.keyUsageCritical=true\npolicyset.userCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.userCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.7.constraint.name=No Constraint\npolicyset.userCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.userCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.userCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.userCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.userCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.8.constraint.name=No Constraint\npolicyset.userCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.userCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.userCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.userCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.userCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.userCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.userCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.userCertSet.9.constraint.name=No Constraint\npolicyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.userCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.userCertSet.9.default.name=Signing Alg\npolicyset.userCertSet.9.default.params.signingAlg=-\nprofileId=caECDirUserCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:15Z DEBUG response status 409 2020-06-17T10:09:15Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:15Z DEBUG Error migrating 'caECDirUserCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:15Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caECDirUserCert?action=enable 2020-06-17T10:09:15Z DEBUG request body '' 2020-06-17T10:09:15Z DEBUG response status 409 2020-06-17T10:09:15Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:15Z DEBUG Failed to enable profile 'caECDirUserCert' (it is probably already enabled) 2020-06-17T10:09:15Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:15Z DEBUG request body '' 2020-06-17T10:09:15Z DEBUG response status 204 2020-06-17T10:09:15Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=F2CD3BABBF952C982B4F82E66EC28F2A; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'' 2020-06-17T10:09:15Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:15Z DEBUG request body '' 2020-06-17T10:09:15Z DEBUG response status 200 2020-06-17T10:09:15Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=14ED389AA7007D1F762C1D205E333153; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:15Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:15Z DEBUG request body 'desc=This certificate profile is for enrolling server certificates with agent authentication.\nvisible=true\nenable=true\nenableBy=admin\nauth.instance_id=AgentCertAuth\nname=Agent-Authenticated Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=365\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=180\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name Extension\nprofileId=caAgentServerCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:15Z DEBUG response status 409 2020-06-17T10:09:15Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:15Z DEBUG Error migrating 'caAgentServerCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:15Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caAgentServerCert?action=enable 2020-06-17T10:09:15Z DEBUG request body '' 2020-06-17T10:09:15Z DEBUG response status 409 2020-06-17T10:09:15Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:15Z DEBUG Failed to enable profile 'caAgentServerCert' (it is probably already enabled) 2020-06-17T10:09:15Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:15Z DEBUG request body '' 2020-06-17T10:09:15Z DEBUG response status 204 2020-06-17T10:09:15Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=E2A8F712D2182C789CDF3D9568ACF119; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'' 2020-06-17T10:09:15Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:15Z DEBUG request body '' 2020-06-17T10:09:15Z DEBUG response status 200 2020-06-17T10:09:15Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=8640592BDDDB9795A3E0E96EC93AA778; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:15Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:15Z DEBUG request body 'desc=This certificate profile is for enrolling server certificates with ECC keys using agent authentication.\nvisible=true\nenable=true\nenableBy=admin\nauth.instance_id=AgentCertAuth\nname=Agent-Authenticated Server Certificate Enrollment with ECC keys\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=365\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=180\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=-\npolicyset.serverCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name Extension\nprofileId=caECAgentServerCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:15Z DEBUG response status 409 2020-06-17T10:09:15Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:15Z DEBUG Error migrating 'caECAgentServerCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:15Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caECAgentServerCert?action=enable 2020-06-17T10:09:15Z DEBUG request body '' 2020-06-17T10:09:15Z DEBUG response status 409 2020-06-17T10:09:15Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:15Z DEBUG Failed to enable profile 'caECAgentServerCert' (it is probably already enabled) 2020-06-17T10:09:15Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:15Z DEBUG request body '' 2020-06-17T10:09:15Z DEBUG response status 204 2020-06-17T10:09:15Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=9CB5EF95B6270325D03A1DDF6A345E59; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'' 2020-06-17T10:09:15Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:15Z DEBUG request body '' 2020-06-17T10:09:15Z DEBUG response status 200 2020-06-17T10:09:15Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=397764A3895CA58446BF6EA13693D186; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:15Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:15Z DEBUG request body 'desc=This certificate profile is for getting file signing certificate with agent authentication.\nvisible=true\nenable=true\nenableBy=admin\nauth.instance_id=AgentCertAuth\nname=Agent-Authenticated File Signing\ninput.list=i1,i2,i3\ninput.i1.class_id=keyGenInputImpl\ninput.i2.class_id=fileSigningInputImpl\ninput.i3.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=pkcs7OutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=CN=(Name)$request.requestor_name$(Text)$request.file_signing_text$(Size)$request.file_signing_size$(DigestType)$request.file_signing_digest_type$(Digest)$request.file_signing_digest$\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=365\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=180\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.3\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\nprofileId=caAgentFileSigning\nclassId=caEnrollImpl\n' 2020-06-17T10:09:15Z DEBUG response status 409 2020-06-17T10:09:15Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:15Z DEBUG Error migrating 'caAgentFileSigning': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:15Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caAgentFileSigning?action=enable 2020-06-17T10:09:15Z DEBUG request body '' 2020-06-17T10:09:15Z DEBUG response status 409 2020-06-17T10:09:15Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:15Z DEBUG Failed to enable profile 'caAgentFileSigning' (it is probably already enabled) 2020-06-17T10:09:15Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:15Z DEBUG request body '' 2020-06-17T10:09:15Z DEBUG response status 204 2020-06-17T10:09:15Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=370C9201DF5AC35001B811E44B8BCB83; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:15Z DEBUG response body (decoded): b'' 2020-06-17T10:09:15Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:15Z DEBUG request body '' 2020-06-17T10:09:16Z DEBUG response status 200 2020-06-17T10:09:16Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=975D4A3BF5592C7BBB3318E39DEB16DE; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:16Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:16Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates by using the CMC certificate request with CMC Signature authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=Signed CMC-Authenticated User Certificate Enrollment\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=cmcUserCertSet\npolicyset.cmcUserCertSet.list=1,2,3,4,5,6,7,8\npolicyset.cmcUserCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.cmcUserCertSet.1.constraint.name=Subject Name Constraint\npolicyset.cmcUserCertSet.1.constraint.params.pattern=.*\npolicyset.cmcUserCertSet.1.constraint.params.accept=true\npolicyset.cmcUserCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.cmcUserCertSet.1.default.name=Subject Name Default\npolicyset.cmcUserCertSet.1.default.params.name=\npolicyset.cmcUserCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.cmcUserCertSet.2.constraint.name=Validity Constraint\npolicyset.cmcUserCertSet.2.constraint.params.range=365\npolicyset.cmcUserCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.notAfterCheck=false\npolicyset.cmcUserCertSet.2.default.class_id=validityDefaultImpl\npolicyset.cmcUserCertSet.2.default.name=Validity Default\npolicyset.cmcUserCertSet.2.default.params.range=180\npolicyset.cmcUserCertSet.2.default.params.startTime=0\npolicyset.cmcUserCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.cmcUserCertSet.3.constraint.name=Key Constraint\npolicyset.cmcUserCertSet.3.constraint.params.keyType=RSA\npolicyset.cmcUserCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.cmcUserCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.cmcUserCertSet.3.default.name=Key Default\npolicyset.cmcUserCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.4.constraint.name=No Constraint\npolicyset.cmcUserCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.cmcUserCertSet.4.default.name=Authority Key Identifier Default\npolicyset.cmcUserCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.5.constraint.name=No Constraint\npolicyset.cmcUserCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.cmcUserCertSet.5.default.name=AIA Extension Default\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.cmcUserCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.cmcUserCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.6.default.name=Key Usage Default\npolicyset.cmcUserCertSet.6.default.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.7.constraint.name=No Constraint\npolicyset.cmcUserCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.cmcUserCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.cmcUserCertSet.8.constraint.name=No Constraint\npolicyset.cmcUserCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.cmcUserCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.cmcUserCertSet.8.default.name=Signing Alg\npolicyset.cmcUserCertSet.8.default.params.signingAlg=-\nprofileId=caCMCUserCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:16Z DEBUG response status 409 2020-06-17T10:09:16Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:16Z DEBUG Error migrating 'caCMCUserCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:16Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caCMCUserCert?action=enable 2020-06-17T10:09:16Z DEBUG request body '' 2020-06-17T10:09:16Z DEBUG response status 409 2020-06-17T10:09:16Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:16Z DEBUG Failed to enable profile 'caCMCUserCert' (it is probably already enabled) 2020-06-17T10:09:16Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:16Z DEBUG request body '' 2020-06-17T10:09:16Z DEBUG response status 204 2020-06-17T10:09:16Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=11DF05EA51B746148F6D28A8AB8D5FBB; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'' 2020-06-17T10:09:16Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:16Z DEBUG request body '' 2020-06-17T10:09:16Z DEBUG response status 200 2020-06-17T10:09:16Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=27E9F3033A53C4FB59A8BF4B6F2520EB; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:16Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:16Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates with ECC keys by using the CMC certificate request with CMC Signature authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=Signed CMC-Authenticated User Certificate wth ECC keys Enrollment\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=cmcUserCertSet\npolicyset.cmcUserCertSet.list=1,2,3,4,5,6,7,8\npolicyset.cmcUserCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.cmcUserCertSet.1.constraint.name=Subject Name Constraint\npolicyset.cmcUserCertSet.1.constraint.params.pattern=.*\npolicyset.cmcUserCertSet.1.constraint.params.accept=true\npolicyset.cmcUserCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.cmcUserCertSet.1.default.name=Subject Name Default\npolicyset.cmcUserCertSet.1.default.params.name=\npolicyset.cmcUserCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.cmcUserCertSet.2.constraint.name=Validity Constraint\npolicyset.cmcUserCertSet.2.constraint.params.range=365\npolicyset.cmcUserCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.notAfterCheck=false\npolicyset.cmcUserCertSet.2.default.class_id=validityDefaultImpl\npolicyset.cmcUserCertSet.2.default.name=Validity Default\npolicyset.cmcUserCertSet.2.default.params.range=180\npolicyset.cmcUserCertSet.2.default.params.startTime=0\npolicyset.cmcUserCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.cmcUserCertSet.3.constraint.name=Key Constraint\npolicyset.cmcUserCertSet.3.constraint.params.keyType=EC\npolicyset.cmcUserCertSet.3.constraint.params.keyParameters=nistp256,nistp521\npolicyset.cmcUserCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.cmcUserCertSet.3.default.name=Key Default\npolicyset.cmcUserCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.4.constraint.name=No Constraint\npolicyset.cmcUserCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.cmcUserCertSet.4.default.name=Authority Key Identifier Default\npolicyset.cmcUserCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.5.constraint.name=No Constraint\npolicyset.cmcUserCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.cmcUserCertSet.5.default.name=AIA Extension Default\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.cmcUserCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.cmcUserCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.6.default.name=Key Usage Default\npolicyset.cmcUserCertSet.6.default.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.7.constraint.name=No Constraint\npolicyset.cmcUserCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.cmcUserCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.cmcUserCertSet.8.constraint.name=No Constraint\npolicyset.cmcUserCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.cmcUserCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.cmcUserCertSet.8.default.name=Signing Alg\npolicyset.cmcUserCertSet.8.default.params.signingAlg=-\nprofileId=caCMCECUserCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:16Z DEBUG response status 409 2020-06-17T10:09:16Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:16Z DEBUG Error migrating 'caCMCECUserCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:16Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caCMCECUserCert?action=enable 2020-06-17T10:09:16Z DEBUG request body '' 2020-06-17T10:09:16Z DEBUG response status 409 2020-06-17T10:09:16Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:16Z DEBUG Failed to enable profile 'caCMCECUserCert' (it is probably already enabled) 2020-06-17T10:09:16Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:16Z DEBUG request body '' 2020-06-17T10:09:16Z DEBUG response status 204 2020-06-17T10:09:16Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=DF0F23FD36CD8AC1AE45C402203AEE34; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:15 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'' 2020-06-17T10:09:16Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:16Z DEBUG request body '' 2020-06-17T10:09:16Z DEBUG response status 200 2020-06-17T10:09:16Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=16817797788026871277EFC20D8D1852; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:16Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:16Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates by using the agent-signed CMC certificate request with CMC Signature authentication.\nenable=true\nenableBy=admin\nname=Agent-Signed CMC-Authenticated User Certificate Enrollment\nvisible=false\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=cmcUserCertSet\npolicyset.cmcUserCertSet.list=1,2,3,4,5,6,7,8\npolicyset.cmcUserCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.cmcUserCertSet.1.constraint.name=Subject Name Constraint\npolicyset.cmcUserCertSet.1.constraint.params.accept=true\npolicyset.cmcUserCertSet.1.constraint.params.pattern=.*\npolicyset.cmcUserCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.cmcUserCertSet.1.default.name=Subject Name Default\npolicyset.cmcUserCertSet.1.default.params.name=\npolicyset.cmcUserCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.cmcUserCertSet.2.constraint.name=Validity Constraint\npolicyset.cmcUserCertSet.2.constraint.params.notAfterCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.range=365\npolicyset.cmcUserCertSet.2.default.class_id=validityDefaultImpl\npolicyset.cmcUserCertSet.2.default.name=Validity Default\npolicyset.cmcUserCertSet.2.default.params.range=180\npolicyset.cmcUserCertSet.2.default.params.startTime=0\npolicyset.cmcUserCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.cmcUserCertSet.3.constraint.name=Key Constraint\npolicyset.cmcUserCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.cmcUserCertSet.3.constraint.params.keyType=RSA\npolicyset.cmcUserCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.cmcUserCertSet.3.default.name=Key Default\npolicyset.cmcUserCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.4.constraint.name=No Constraint\npolicyset.cmcUserCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.cmcUserCertSet.4.default.name=Authority Key Identifier Default\npolicyset.cmcUserCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.5.constraint.name=No Constraint\npolicyset.cmcUserCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.cmcUserCertSet.5.default.name=AIA Extension Default\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.cmcUserCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.cmcUserCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.6.default.name=Key Usage Default\npolicyset.cmcUserCertSet.6.default.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.7.constraint.name=No Constraint\npolicyset.cmcUserCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.cmcUserCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.cmcUserCertSet.8.constraint.name=No Constraint\npolicyset.cmcUserCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.cmcUserCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.cmcUserCertSet.8.default.name=Signing Alg\npolicyset.cmcUserCertSet.8.default.params.signingAlg=-\nprofileId=caFullCMCUserCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:16Z DEBUG response status 409 2020-06-17T10:09:16Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:16Z DEBUG Error migrating 'caFullCMCUserCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:16Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caFullCMCUserCert?action=enable 2020-06-17T10:09:16Z DEBUG request body '' 2020-06-17T10:09:16Z DEBUG response status 409 2020-06-17T10:09:16Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:16Z DEBUG Failed to enable profile 'caFullCMCUserCert' (it is probably already enabled) 2020-06-17T10:09:16Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:16Z DEBUG request body '' 2020-06-17T10:09:16Z DEBUG response status 204 2020-06-17T10:09:16Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=6F8A9B15906BD4F09DA3DCAF286D4B04; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'' 2020-06-17T10:09:16Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:16Z DEBUG request body '' 2020-06-17T10:09:16Z DEBUG response status 200 2020-06-17T10:09:16Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=4BF65FE00B97697F195A11C9A950C6C0; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:16Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:16Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates by using the agent-signed CMC certificate request with CMC Signature authentication.\nenable=true\nenableBy=admin\nname=Agent-Signed CMC-Authenticated User Certificate Enrollment\nvisible=false\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=cmcUserCertSet\npolicyset.cmcUserCertSet.list=1,2,3,4,5,6,7,8\npolicyset.cmcUserCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.cmcUserCertSet.1.constraint.name=Subject Name Constraint\npolicyset.cmcUserCertSet.1.constraint.params.accept=true\npolicyset.cmcUserCertSet.1.constraint.params.pattern=.*\npolicyset.cmcUserCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.cmcUserCertSet.1.default.name=Subject Name Default\npolicyset.cmcUserCertSet.1.default.params.name=\npolicyset.cmcUserCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.cmcUserCertSet.2.constraint.name=Validity Constraint\npolicyset.cmcUserCertSet.2.constraint.params.notAfterCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.range=365\npolicyset.cmcUserCertSet.2.default.class_id=validityDefaultImpl\npolicyset.cmcUserCertSet.2.default.name=Validity Default\npolicyset.cmcUserCertSet.2.default.params.range=180\npolicyset.cmcUserCertSet.2.default.params.startTime=0\npolicyset.cmcUserCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.cmcUserCertSet.3.constraint.name=Key Constraint\npolicyset.cmcUserCertSet.3.constraint.params.keyParameters=nistp256,nistp521\npolicyset.cmcUserCertSet.3.constraint.params.keyType=EC\npolicyset.cmcUserCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.cmcUserCertSet.3.default.name=Key Default\npolicyset.cmcUserCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.4.constraint.name=No Constraint\npolicyset.cmcUserCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.cmcUserCertSet.4.default.name=Authority Key Identifier Default\npolicyset.cmcUserCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.5.constraint.name=No Constraint\npolicyset.cmcUserCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.cmcUserCertSet.5.default.name=AIA Extension Default\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.cmcUserCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.cmcUserCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.6.default.name=Key Usage Default\npolicyset.cmcUserCertSet.6.default.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.7.constraint.name=No Constraint\npolicyset.cmcUserCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.cmcUserCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.cmcUserCertSet.8.constraint.name=No Constraint\npolicyset.cmcUserCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.cmcUserCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.cmcUserCertSet.8.default.name=Signing Alg\npolicyset.cmcUserCertSet.8.default.params.signingAlg=-\nprofileId=caECFullCMCUserCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:16Z DEBUG response status 409 2020-06-17T10:09:16Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:16Z DEBUG Error migrating 'caECFullCMCUserCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:16Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caECFullCMCUserCert?action=enable 2020-06-17T10:09:16Z DEBUG request body '' 2020-06-17T10:09:16Z DEBUG response status 409 2020-06-17T10:09:16Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:16Z DEBUG Failed to enable profile 'caECFullCMCUserCert' (it is probably already enabled) 2020-06-17T10:09:16Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:16Z DEBUG request body '' 2020-06-17T10:09:16Z DEBUG response status 204 2020-06-17T10:09:16Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=B2613C7C3F2D7666469DF72FE8679365; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'' 2020-06-17T10:09:16Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:16Z DEBUG request body '' 2020-06-17T10:09:16Z DEBUG response status 200 2020-06-17T10:09:16Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=4C2F6DE72AF291205EBCC6DCABB5559B; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:16Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:16Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates by using the CMC certificate request with non-agent user CMC authentication.\nenable=false\nenableBy=admin\nname=User-Signed CMC-Authenticated User Certificate Enrollment\nvisible=false\nauth.instance_id=CMCUserSignedAuth\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=cmcUserCertSet\npolicyset.cmcUserCertSet.list=1,9,10,2,3,4,5,6,7,8\npolicyset.cmcUserCertSet.1.constraint.class_id=cmcUserSignedSubjectNameConstraintImpl\npolicyset.cmcUserCertSet.1.constraint.name=CMC User Signed Subject Name Constraint\npolicyset.cmcUserCertSet.1.default.class_id=cmcUserSignedSubjectNameDefaultImpl\npolicyset.cmcUserCertSet.1.default.name=User Signed Subject Name Default\npolicyset.cmcUserCertSet.1.default.params.name=\npolicyset.cmcUserCertSet.9.constraint.class_id=uniqueKeyConstraintImpl\npolicyset.cmcUserCertSet.9.constraint.name=Unique Key Constraint\npolicyset.cmcUserCertSet.9.constraint.params.allowSameKeyRenewal=true\npolicyset.cmcUserCertSet.9.default.class_id=noDefaultImpl\npolicyset.cmcUserCertSet.9.default.name=No Default\npolicyset.cmcUserCertSet.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.cmcUserCertSet.10.constraint.name=Renewal Grace Period Constraint\npolicyset.cmcUserCertSet.10.constraint.params.renewal.graceBefore=30\npolicyset.cmcUserCertSet.10.constraint.params.renewal.graceAfter=30\npolicyset.cmcUserCertSet.10.default.class_id=noDefaultImpl\npolicyset.cmcUserCertSet.10.default.name=No Default\npolicyset.cmcUserCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.cmcUserCertSet.2.constraint.name=Validity Constraint\npolicyset.cmcUserCertSet.2.constraint.params.notAfterCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.range=365\npolicyset.cmcUserCertSet.2.default.class_id=validityDefaultImpl\npolicyset.cmcUserCertSet.2.default.name=Validity Default\npolicyset.cmcUserCertSet.2.default.params.range=180\npolicyset.cmcUserCertSet.2.default.params.startTime=0\npolicyset.cmcUserCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.cmcUserCertSet.3.constraint.name=Key Constraint\npolicyset.cmcUserCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.cmcUserCertSet.3.constraint.params.keyType=RSA\npolicyset.cmcUserCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.cmcUserCertSet.3.default.name=Key Default\npolicyset.cmcUserCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.4.constraint.name=No Constraint\npolicyset.cmcUserCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.cmcUserCertSet.4.default.name=Authority Key Identifier Default\npolicyset.cmcUserCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.5.constraint.name=No Constraint\npolicyset.cmcUserCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.cmcUserCertSet.5.default.name=AIA Extension Default\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.cmcUserCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.cmcUserCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.6.default.name=Key Usage Default\npolicyset.cmcUserCertSet.6.default.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.7.constraint.name=No Constraint\npolicyset.cmcUserCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.cmcUserCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.cmcUserCertSet.8.constraint.name=No Constraint\npolicyset.cmcUserCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.cmcUserCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.cmcUserCertSet.8.default.name=Signing Alg\npolicyset.cmcUserCertSet.8.default.params.signingAlg=-\nprofileId=caFullCMCUserSignedCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:16Z DEBUG response status 409 2020-06-17T10:09:16Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:16Z DEBUG Error migrating 'caFullCMCUserSignedCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:16Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caFullCMCUserSignedCert?action=enable 2020-06-17T10:09:16Z DEBUG request body '' 2020-06-17T10:09:16Z DEBUG response status 204 2020-06-17T10:09:16Z DEBUG response headers Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'' 2020-06-17T10:09:16Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:16Z DEBUG request body '' 2020-06-17T10:09:16Z DEBUG response status 204 2020-06-17T10:09:16Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=57A71A001A0374786EA405459563FA45; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'' 2020-06-17T10:09:16Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:16Z DEBUG request body '' 2020-06-17T10:09:16Z DEBUG response status 200 2020-06-17T10:09:16Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=CFE8D924946399420F2340277F1BEA42; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:16Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:16Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates with EC keys by using the CMC certificate request with non-agent user CMC authentication.\nenable=false\nenableBy=admin\nname=User-Signed CMC-Authenticated User Certificate Enrollment\nvisible=false\nauth.instance_id=CMCUserSignedAuth\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=cmcUserCertSet\npolicyset.cmcUserCertSet.list=1,9,10,2,3,4,5,6,7,8\npolicyset.cmcUserCertSet.1.constraint.class_id=cmcUserSignedSubjectNameConstraintImpl\npolicyset.cmcUserCertSet.1.constraint.name=CMC User Signed Subject Name Constraint\npolicyset.cmcUserCertSet.1.default.class_id=cmcUserSignedSubjectNameDefaultImpl\npolicyset.cmcUserCertSet.1.default.name=User Signed Subject Name Default\npolicyset.cmcUserCertSet.1.default.params.name=\npolicyset.cmcUserCertSet.9.constraint.class_id=uniqueKeyConstraintImpl\npolicyset.cmcUserCertSet.9.constraint.name=Unique Key Constraint\npolicyset.cmcUserCertSet.9.constraint.params.allowSameKeyRenewal=true\npolicyset.cmcUserCertSet.9.default.class_id=noDefaultImpl\npolicyset.cmcUserCertSet.9.default.name=No Default\npolicyset.cmcUserCertSet.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.cmcUserCertSet.10.constraint.name=Renewal Grace Period Constraint\npolicyset.cmcUserCertSet.10.constraint.params.renewal.graceBefore=30\npolicyset.cmcUserCertSet.10.constraint.params.renewal.graceAfter=30\npolicyset.cmcUserCertSet.10.default.class_id=noDefaultImpl\npolicyset.cmcUserCertSet.10.default.name=No Default\npolicyset.cmcUserCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.cmcUserCertSet.2.constraint.name=Validity Constraint\npolicyset.cmcUserCertSet.2.constraint.params.notAfterCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.range=365\npolicyset.cmcUserCertSet.2.default.class_id=validityDefaultImpl\npolicyset.cmcUserCertSet.2.default.name=Validity Default\npolicyset.cmcUserCertSet.2.default.params.range=180\npolicyset.cmcUserCertSet.2.default.params.startTime=0\npolicyset.cmcUserCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.cmcUserCertSet.3.constraint.name=Key Constraint\npolicyset.cmcUserCertSet.3.constraint.params.keyParameters=nistp256,nistp521\npolicyset.cmcUserCertSet.3.constraint.params.keyType=EC\npolicyset.cmcUserCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.cmcUserCertSet.3.default.name=Key Default\npolicyset.cmcUserCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.4.constraint.name=No Constraint\npolicyset.cmcUserCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.cmcUserCertSet.4.default.name=Authority Key Identifier Default\npolicyset.cmcUserCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.5.constraint.name=No Constraint\npolicyset.cmcUserCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.cmcUserCertSet.5.default.name=AIA Extension Default\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.cmcUserCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.cmcUserCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.6.default.name=Key Usage Default\npolicyset.cmcUserCertSet.6.default.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.7.constraint.name=No Constraint\npolicyset.cmcUserCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.cmcUserCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.cmcUserCertSet.8.constraint.name=No Constraint\npolicyset.cmcUserCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.cmcUserCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.cmcUserCertSet.8.default.name=Signing Alg\npolicyset.cmcUserCertSet.8.default.params.signingAlg=-\nprofileId=caECFullCMCUserSignedCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:16Z DEBUG response status 409 2020-06-17T10:09:16Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:16Z DEBUG Error migrating 'caECFullCMCUserSignedCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:16Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caECFullCMCUserSignedCert?action=enable 2020-06-17T10:09:16Z DEBUG request body '' 2020-06-17T10:09:16Z DEBUG response status 204 2020-06-17T10:09:16Z DEBUG response headers Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'' 2020-06-17T10:09:16Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:16Z DEBUG request body '' 2020-06-17T10:09:16Z DEBUG response status 204 2020-06-17T10:09:16Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=E032A0C978DC76C6653A0B05DC013927; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'' 2020-06-17T10:09:16Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:16Z DEBUG request body '' 2020-06-17T10:09:16Z DEBUG response status 200 2020-06-17T10:09:16Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=A7F80A68CB146C981CD3AE4533B10477; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:16Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:16Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:16Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates by using the CMC Shared Token certificate request\nenable=false\nenableBy=admin\nname=CMC Shared Token User Certificate Enrollment\nvisible=false\nauth.instance_id=CMCUserSignedAuth\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=cmcUserCertSet\npolicyset.cmcUserCertSet.list=1,2,3,4,5,6,7,8\npolicyset.cmcUserCertSet.1.constraint.class_id=cmcSharedTokenSubjectNameConstraintImpl\npolicyset.cmcUserCertSet.1.constraint.name=CMC Shared Token Subject Name Constraint\npolicyset.cmcUserCertSet.1.default.class_id=authTokenSubjectNameDefaultImpl\npolicyset.cmcUserCertSet.1.default.name=Subject Name Default\npolicyset.cmcUserCertSet.1.default.params.name=\npolicyset.cmcUserCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.cmcUserCertSet.2.constraint.name=Validity Constraint\npolicyset.cmcUserCertSet.2.constraint.params.notAfterCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.range=365\npolicyset.cmcUserCertSet.2.default.class_id=validityDefaultImpl\npolicyset.cmcUserCertSet.2.default.name=Validity Default\npolicyset.cmcUserCertSet.2.default.params.range=180\npolicyset.cmcUserCertSet.2.default.params.startTime=0\npolicyset.cmcUserCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.cmcUserCertSet.3.constraint.name=Key Constraint\npolicyset.cmcUserCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.cmcUserCertSet.3.constraint.params.keyType=RSA\npolicyset.cmcUserCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.cmcUserCertSet.3.default.name=Key Default\npolicyset.cmcUserCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.4.constraint.name=No Constraint\npolicyset.cmcUserCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.cmcUserCertSet.4.default.name=Authority Key Identifier Default\npolicyset.cmcUserCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.5.constraint.name=No Constraint\npolicyset.cmcUserCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.cmcUserCertSet.5.default.name=AIA Extension Default\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.cmcUserCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.cmcUserCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.6.default.name=Key Usage Default\npolicyset.cmcUserCertSet.6.default.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.7.constraint.name=No Constraint\npolicyset.cmcUserCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.cmcUserCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.cmcUserCertSet.8.constraint.name=No Constraint\npolicyset.cmcUserCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.cmcUserCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.cmcUserCertSet.8.default.name=Signing Alg\npolicyset.cmcUserCertSet.8.default.params.signingAlg=-\nprofileId=caFullCMCSharedTokenCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:17Z DEBUG response status 409 2020-06-17T10:09:17Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:17Z DEBUG Error migrating 'caFullCMCSharedTokenCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:17Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caFullCMCSharedTokenCert?action=enable 2020-06-17T10:09:17Z DEBUG request body '' 2020-06-17T10:09:17Z DEBUG response status 204 2020-06-17T10:09:17Z DEBUG response headers Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'' 2020-06-17T10:09:17Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:17Z DEBUG request body '' 2020-06-17T10:09:17Z DEBUG response status 204 2020-06-17T10:09:17Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=68C6B5A335043ABC6B3E0FC7B639B581; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'' 2020-06-17T10:09:17Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:17Z DEBUG request body '' 2020-06-17T10:09:17Z DEBUG response status 200 2020-06-17T10:09:17Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=DD50AB54F92D51AADF5E046BC63E875E; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:17Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:17Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates with ECC keys by using the CMC Shared Token certificate request\nenable=false\nenableBy=admin\nname=CMC Shared Token User Certificate Enrollment\nvisible=false\nauth.instance_id=CMCUserSignedAuth\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=cmcUserCertSet\npolicyset.cmcUserCertSet.list=1,2,3,4,5,6,7,8\npolicyset.cmcUserCertSet.1.constraint.class_id=cmcSharedTokenSubjectNameConstraintImpl\npolicyset.cmcUserCertSet.1.constraint.name=CMC Shared Token Subject Name Constraint\npolicyset.cmcUserCertSet.1.default.class_id=authTokenSubjectNameDefaultImpl\npolicyset.cmcUserCertSet.1.default.name=Subject Name Default\npolicyset.cmcUserCertSet.1.default.params.name=\npolicyset.cmcUserCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.cmcUserCertSet.2.constraint.name=Validity Constraint\npolicyset.cmcUserCertSet.2.constraint.params.notAfterCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.range=365\npolicyset.cmcUserCertSet.2.default.class_id=validityDefaultImpl\npolicyset.cmcUserCertSet.2.default.name=Validity Default\npolicyset.cmcUserCertSet.2.default.params.range=180\npolicyset.cmcUserCertSet.2.default.params.startTime=0\npolicyset.cmcUserCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.cmcUserCertSet.3.constraint.name=Key Constraint\npolicyset.cmcUserCertSet.3.constraint.params.keyParameters=nistp256,nistp521\npolicyset.cmcUserCertSet.3.constraint.params.keyType=EC\npolicyset.cmcUserCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.cmcUserCertSet.3.default.name=Key Default\npolicyset.cmcUserCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.4.constraint.name=No Constraint\npolicyset.cmcUserCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.cmcUserCertSet.4.default.name=Authority Key Identifier Default\npolicyset.cmcUserCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.5.constraint.name=No Constraint\npolicyset.cmcUserCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.cmcUserCertSet.5.default.name=AIA Extension Default\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.cmcUserCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.cmcUserCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.6.default.name=Key Usage Default\npolicyset.cmcUserCertSet.6.default.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.7.constraint.name=No Constraint\npolicyset.cmcUserCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.cmcUserCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.cmcUserCertSet.8.constraint.name=No Constraint\npolicyset.cmcUserCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.cmcUserCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.cmcUserCertSet.8.default.name=Signing Alg\npolicyset.cmcUserCertSet.8.default.params.signingAlg=-\nprofileId=caECFullCMCSharedTokenCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:17Z DEBUG response status 409 2020-06-17T10:09:17Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:17Z DEBUG Error migrating 'caECFullCMCSharedTokenCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:17Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caECFullCMCSharedTokenCert?action=enable 2020-06-17T10:09:17Z DEBUG request body '' 2020-06-17T10:09:17Z DEBUG response status 204 2020-06-17T10:09:17Z DEBUG response headers Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'' 2020-06-17T10:09:17Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:17Z DEBUG request body '' 2020-06-17T10:09:17Z DEBUG response status 204 2020-06-17T10:09:17Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=2263680E1C3FB7296DCC34800F21CD8F; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'' 2020-06-17T10:09:17Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:17Z DEBUG request body '' 2020-06-17T10:09:17Z DEBUG response status 200 2020-06-17T10:09:17Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=E265160958E0D5B1C53EEDA048D8C144; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:16 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:17Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:17Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates by using the CMC Simple certificate request with agent authentication.\nenable=true\nenableBy=admin\nname=Simple CMC Enrollment Request for User Certificate\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1\ninput.i1.class_id=certReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=cmcUserCertSet\npolicyset.cmcUserCertSet.list=1,2,3,4,5,6,7,8\npolicyset.cmcUserCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.cmcUserCertSet.1.constraint.name=Subject Name Constraint\npolicyset.cmcUserCertSet.1.constraint.params.accept=true\npolicyset.cmcUserCertSet.1.constraint.params.pattern=.*\npolicyset.cmcUserCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.cmcUserCertSet.1.default.name=Subject Name Default\npolicyset.cmcUserCertSet.1.default.params.name=\npolicyset.cmcUserCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.cmcUserCertSet.2.constraint.name=Validity Constraint\npolicyset.cmcUserCertSet.2.constraint.params.notAfterCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.range=365\npolicyset.cmcUserCertSet.2.default.class_id=validityDefaultImpl\npolicyset.cmcUserCertSet.2.default.name=Validity Default\npolicyset.cmcUserCertSet.2.default.params.range=180\npolicyset.cmcUserCertSet.2.default.params.startTime=0\npolicyset.cmcUserCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.cmcUserCertSet.3.constraint.name=Key Constraint\npolicyset.cmcUserCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.cmcUserCertSet.3.constraint.params.keyType=RSA\npolicyset.cmcUserCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.cmcUserCertSet.3.default.name=Key Default\npolicyset.cmcUserCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.4.constraint.name=No Constraint\npolicyset.cmcUserCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.cmcUserCertSet.4.default.name=Authority Key Identifier Default\npolicyset.cmcUserCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.5.constraint.name=No Constraint\npolicyset.cmcUserCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.cmcUserCertSet.5.default.name=AIA Extension Default\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.cmcUserCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.cmcUserCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.6.default.name=Key Usage Default\npolicyset.cmcUserCertSet.6.default.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.7.constraint.name=No Constraint\npolicyset.cmcUserCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.cmcUserCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.cmcUserCertSet.8.constraint.name=No Constraint\npolicyset.cmcUserCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.cmcUserCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.cmcUserCertSet.8.default.name=Signing Alg\npolicyset.cmcUserCertSet.8.default.params.signingAlg=-\nprofileId=caSimpleCMCUserCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:17Z DEBUG response status 409 2020-06-17T10:09:17Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:17Z DEBUG Error migrating 'caSimpleCMCUserCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:17Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caSimpleCMCUserCert?action=enable 2020-06-17T10:09:17Z DEBUG request body '' 2020-06-17T10:09:17Z DEBUG response status 409 2020-06-17T10:09:17Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:17Z DEBUG Failed to enable profile 'caSimpleCMCUserCert' (it is probably already enabled) 2020-06-17T10:09:17Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:17Z DEBUG request body '' 2020-06-17T10:09:17Z DEBUG response status 204 2020-06-17T10:09:17Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=00BEC04E91995CA86DE7A47648C7C7C4; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'' 2020-06-17T10:09:17Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:17Z DEBUG request body '' 2020-06-17T10:09:17Z DEBUG response status 200 2020-06-17T10:09:17Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=A436A2D2C2CAB6CF7FB8E8F8A5FD95F8; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:17Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:17Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates by using the CMC simple certificate request with agent authentication.\nenable=true\nenableBy=admin\nname=Simple CMC Enrollment Request for User Certificate\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1\ninput.i1.class_id=certReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=cmcUserCertSet\npolicyset.cmcUserCertSet.list=1,2,3,4,5,6,7,8\npolicyset.cmcUserCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.cmcUserCertSet.1.constraint.name=Subject Name Constraint\npolicyset.cmcUserCertSet.1.constraint.params.accept=true\npolicyset.cmcUserCertSet.1.constraint.params.pattern=.*\npolicyset.cmcUserCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.cmcUserCertSet.1.default.name=Subject Name Default\npolicyset.cmcUserCertSet.1.default.params.name=\npolicyset.cmcUserCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.cmcUserCertSet.2.constraint.name=Validity Constraint\npolicyset.cmcUserCertSet.2.constraint.params.notAfterCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.range=365\npolicyset.cmcUserCertSet.2.default.class_id=validityDefaultImpl\npolicyset.cmcUserCertSet.2.default.name=Validity Default\npolicyset.cmcUserCertSet.2.default.params.range=180\npolicyset.cmcUserCertSet.2.default.params.startTime=0\npolicyset.cmcUserCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.cmcUserCertSet.3.constraint.name=Key Constraint\npolicyset.cmcUserCertSet.3.constraint.params.keyParameters=nistp256,nistp521\npolicyset.cmcUserCertSet.3.constraint.params.keyType=EC\npolicyset.cmcUserCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.cmcUserCertSet.3.default.name=Key Default\npolicyset.cmcUserCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.4.constraint.name=No Constraint\npolicyset.cmcUserCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.cmcUserCertSet.4.default.name=Authority Key Identifier Default\npolicyset.cmcUserCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.5.constraint.name=No Constraint\npolicyset.cmcUserCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.cmcUserCertSet.5.default.name=AIA Extension Default\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.cmcUserCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.cmcUserCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.6.default.name=Key Usage Default\npolicyset.cmcUserCertSet.6.default.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.7.constraint.name=No Constraint\npolicyset.cmcUserCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.cmcUserCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.cmcUserCertSet.8.constraint.name=No Constraint\npolicyset.cmcUserCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.cmcUserCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.cmcUserCertSet.8.default.name=Signing Alg\npolicyset.cmcUserCertSet.8.default.params.signingAlg=-\nprofileId=caECSimpleCMCUserCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:17Z DEBUG response status 409 2020-06-17T10:09:17Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:17Z DEBUG Error migrating 'caECSimpleCMCUserCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:17Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caECSimpleCMCUserCert?action=enable 2020-06-17T10:09:17Z DEBUG request body '' 2020-06-17T10:09:17Z DEBUG response status 409 2020-06-17T10:09:17Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:17Z DEBUG Failed to enable profile 'caECSimpleCMCUserCert' (it is probably already enabled) 2020-06-17T10:09:17Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:17Z DEBUG request body '' 2020-06-17T10:09:17Z DEBUG response status 204 2020-06-17T10:09:17Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=201242927A8145AFCA288AC9E5675931; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'' 2020-06-17T10:09:17Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:17Z DEBUG request body '' 2020-06-17T10:09:17Z DEBUG response status 200 2020-06-17T10:09:17Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=3B97D07722EDBED68B64F757CD0ABF23; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:17Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:17Z DEBUG request body 'desc=This profile is for enrolling token device keys\nenable=true\nenableBy=admin\nlastModified=1068835451090\nname=Token Device Key Enrollment\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1\ninput.i1.class_id=nsHKeyCertReqInputImpl\ninput.i1.name=nsHKeyCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=nsNKeyOutputImpl\noutput.o2.name=nsNKeyOutputImpl\npolicyset.list=set1\n#policyset.set1.list=p2,p3,p4,p5,p1,p7,p8,p9,p12,p6\npolicyset.set1.list=p2,p4,p5,p1,p8,p9,p12\npolicyset.set1.p1.constraint.class_id=noConstraintImpl\npolicyset.set1.p1.constraint.name=No Constraint\npolicyset.set1.p1.default.class_id=nsTokenDeviceKeySubjectNameDefaultImpl\npolicyset.set1.p1.default.name=nsTokenDeviceKeySubjectNameDefault\npolicyset.set1.p1.default.params.dnpattern=UID=Token Key Device - $request.tokencuid$\npolicyset.set1.p12.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.set1.p12.constraint.name=Basic Constraints Extension Constraint\npolicyset.set1.p12.constraint.params.basicConstraintsCritical=-\npolicyset.set1.p12.constraint.params.basicConstraintsIsCA=-\npolicyset.set1.p12.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.set1.p12.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.set1.p12.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.set1.p12.default.name=Basic Constraints Extension Default\npolicyset.set1.p12.default.params.basicConstraintsCritical=false\npolicyset.set1.p12.default.params.basicConstraintsIsCA=false\npolicyset.set1.p12.default.params.basicConstraintsPathLen=-1\npolicyset.set1.p2.constraint.class_id=noConstraintImpl\npolicyset.set1.p2.constraint.name=No Constraint\npolicyset.set1.p2.default.class_id=validityDefaultImpl\npolicyset.set1.p2.default.name=Validity Default\npolicyset.set1.p2.default.params.range=1825\npolicyset.set1.p2.default.params.startTime=0\npolicyset.set1.p3.constraint.class_id=noConstraintImpl\npolicyset.set1.p3.constraint.name=No Constraint\npolicyset.set1.p3.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p3.default.name=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p3.default.params.crlDistPointsCritical=false\npolicyset.set1.p3.default.params.crlDistPointsNum=1\npolicyset.set1.p3.default.params.crlDistPointsEnable_0=false\npolicyset.set1.p3.default.params.crlDistPointsIssuerName_0=\npolicyset.set1.p3.default.params.crlDistPointsIssuerType_0=\npolicyset.set1.p3.default.params.crlDistPointsPointName_0=\npolicyset.set1.p3.default.params.crlDistPointsPointType_0=URIName\npolicyset.set1.p3.default.params.crlDistPointsReasons_0=\npolicyset.set1.p4.constraint.class_id=noConstraintImpl\npolicyset.set1.p4.constraint.name=No Constraint\npolicyset.set1.p4.default.class_id=signingAlgDefaultImpl\npolicyset.set1.p4.default.name=Signing Algorithm Default\npolicyset.set1.p4.default.params.signingAlg=-\npolicyset.set1.p5.constraint.class_id=noConstraintImpl\npolicyset.set1.p5.constraint.name=No Constraint\npolicyset.set1.p5.default.class_id=keyUsageExtDefaultImpl\npolicyset.set1.p5.default.name=Key Usage Extension Default\npolicyset.set1.p5.default.params.keyUsageCritical=true\npolicyset.set1.p5.default.params.keyUsageCrlSign=false\npolicyset.set1.p5.default.params.keyUsageDataEncipherment=false\npolicyset.set1.p5.default.params.keyUsageDecipherOnly=false\npolicyset.set1.p5.default.params.keyUsageDigitalSignature=true\npolicyset.set1.p5.default.params.keyUsageEncipherOnly=false\npolicyset.set1.p5.default.params.keyUsageKeyAgreement=false\npolicyset.set1.p5.default.params.keyUsageKeyCertSign=false\npolicyset.set1.p5.default.params.keyUsageKeyEncipherment=false\npolicyset.set1.p5.default.params.keyUsageNonRepudiation=false\npolicyset.set1.p7.constraint.class_id=noConstraintImpl\npolicyset.set1.p7.constraint.name=No Constraint\npolicyset.set1.p7.default.class_id=certificatePoliciesExtDefaultImpl\npolicyset.set1.p7.default.name=Certificate Policies Extension Default\npolicyset.set1.p7.default.params.Critical=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p8.constraint.class_id=noConstraintImpl\npolicyset.set1.p8.constraint.name=No Constraint\npolicyset.set1.p8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.set1.p8.default.name=Subject Key Identifier Default\npolicyset.set1.p9.constraint.class_id=noConstraintImpl\npolicyset.set1.p9.constraint.name=No Constraint\npolicyset.set1.p9.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.set1.p9.default.name=Authority Key Identifier Extension Default\npolicyset.set1.p6.constraint.class_id=noConstraintImpl\npolicyset.set1.p6.constraint.name=No Constraint\npolicyset.set1.p6.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.set1.p6.default.name=Subject Alternative Name Extension Default\npolicyset.set1.p6.default.params.subjAltExtGNEnable_0=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_1=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_2=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_3=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_4=false\npolicyset.set1.p6.default.params.subjAltExtPattern_0=\npolicyset.set1.p6.default.params.subjAltExtPattern_1=\npolicyset.set1.p6.default.params.subjAltExtPattern_2=\npolicyset.set1.p6.default.params.subjAltExtPattern_3=\npolicyset.set1.p6.default.params.subjAltExtPattern_4=\npolicyset.set1.p6.default.params.subjAltExtType_0=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_1=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_2=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_3=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_4=RFC822Name\npolicyset.set1.p6.default.params.subjAltNameExtCritical=false\npolicyset.set1.p6.default.params.subjAltNameNumGNs=1\nprofileId=caTokenDeviceKeyEnrollment\nclassId=caUserCertEnrollImpl\n' 2020-06-17T10:09:17Z DEBUG response status 409 2020-06-17T10:09:17Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:17Z DEBUG Error migrating 'caTokenDeviceKeyEnrollment': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:17Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caTokenDeviceKeyEnrollment?action=enable 2020-06-17T10:09:17Z DEBUG request body '' 2020-06-17T10:09:17Z DEBUG response status 409 2020-06-17T10:09:17Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:17Z DEBUG Failed to enable profile 'caTokenDeviceKeyEnrollment' (it is probably already enabled) 2020-06-17T10:09:17Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:17Z DEBUG request body '' 2020-06-17T10:09:17Z DEBUG response status 204 2020-06-17T10:09:17Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=849260986154524824052DCDC114DAEC; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'' 2020-06-17T10:09:17Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:17Z DEBUG request body '' 2020-06-17T10:09:17Z DEBUG response status 200 2020-06-17T10:09:17Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=FEFEC1B36F951CD6954EFABED328166B; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:17Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:17Z DEBUG request body 'desc=This profile is for enrolling Token Encryption key\nenable=true\nenableBy=admin\nname=Token User Encryption Certificate Enrollment\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1\ninput.i1.class_id=nsNKeyCertReqInputImpl\ninput.i1.name=nsNKeyCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=nsNKeyOutputImpl\noutput.o2.name=nsNKeyOutputImpl\npolicyset.list=set1\n#policyset.set1.list=p2,p4,p5,p1,p6,p7,p8,p9,p12,p13,p14\npolicyset.set1.list=p2,p4,p5,p1,p6,p8,p9,p12\npolicyset.set1.p1.constraint.class_id=noConstraintImpl\npolicyset.set1.p1.constraint.name=No Constraint\npolicyset.set1.p1.default.class_id=nsTokenUserKeySubjectNameDefaultImpl\npolicyset.set1.p1.default.name=nsTokenUserKeySubjectNameDefault\npolicyset.set1.p1.default.params.dnpattern=UID=$request.uid$, O=Token Key User\n#changed ldap.enable to true to support SMIME\npolicyset.set1.p1.default.params.ldap.enable=false\npolicyset.set1.p1.default.params.ldap.searchName=uid\npolicyset.set1.p1.default.params.ldapStringAttributes=uid,mail\npolicyset.set1.p1.default.params.ldap.basedn=\npolicyset.set1.p1.default.params.ldap.maxConns=4\npolicyset.set1.p1.default.params.ldap.minConns=1\npolicyset.set1.p1.default.params.ldap.ldapconn.Version=2\npolicyset.set1.p1.default.params.ldap.ldapconn.host=\npolicyset.set1.p1.default.params.ldap.ldapconn.port=\npolicyset.set1.p1.default.params.ldap.ldapconn.secureConn=false\npolicyset.set1.p2.constraint.class_id=noConstraintImpl\npolicyset.set1.p2.constraint.name=No Constraint\npolicyset.set1.p2.default.class_id=validityDefaultImpl\npolicyset.set1.p2.default.name=Validity Default\npolicyset.set1.p2.default.params.range=1825\npolicyset.set1.p2.default.params.startTime=0\npolicyset.set1.p4.constraint.class_id=noConstraintImpl\npolicyset.set1.p4.constraint.name=No Constraint\npolicyset.set1.p4.default.class_id=signingAlgDefaultImpl\npolicyset.set1.p4.default.name=Signing Algorithm Default\npolicyset.set1.p4.default.params.signingAlg=-\npolicyset.set1.p5.constraint.class_id=noConstraintImpl\npolicyset.set1.p5.constraint.name=No Constraint\npolicyset.set1.p5.default.class_id=keyUsageExtDefaultImpl\npolicyset.set1.p5.default.name=Key Usage Extension Default\npolicyset.set1.p5.default.params.keyUsageCritical=true\npolicyset.set1.p5.default.params.keyUsageCrlSign=false\npolicyset.set1.p5.default.params.keyUsageDataEncipherment=false\npolicyset.set1.p5.default.params.keyUsageDecipherOnly=false\npolicyset.set1.p5.default.params.keyUsageDigitalSignature=false\npolicyset.set1.p5.default.params.keyUsageEncipherOnly=false\npolicyset.set1.p5.default.params.keyUsageKeyAgreement=false\npolicyset.set1.p5.default.params.keyUsageKeyCertSign=false\npolicyset.set1.p5.default.params.keyUsageKeyEncipherment=true\npolicyset.set1.p5.default.params.keyUsageNonRepudiation=false\npolicyset.set1.p6.constraint.class_id=noConstraintImpl\npolicyset.set1.p6.constraint.name=No Constraint\npolicyset.set1.p6.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.set1.p6.default.name=Subject Alternative Name Extension Default\npolicyset.set1.p6.default.params.subjAltExtGNEnable_0=true\npolicyset.set1.p6.default.params.subjAltExtGNEnable_1=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_2=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_3=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_4=false\npolicyset.set1.p6.default.params.subjAltExtPattern_0=$request.mail$\npolicyset.set1.p6.default.params.subjAltExtPattern_1=\npolicyset.set1.p6.default.params.subjAltExtPattern_2=\npolicyset.set1.p6.default.params.subjAltExtPattern_3=\npolicyset.set1.p6.default.params.subjAltExtPattern_4=\npolicyset.set1.p6.default.params.subjAltExtType_0=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_1=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_2=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_3=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_4=RFC822Name\npolicyset.set1.p6.default.params.subjAltNameExtCritical=false\npolicyset.set1.p6.default.params.subjAltNameNumGNs=1\npolicyset.set1.p7.constraint.class_id=noConstraintImpl\npolicyset.set1.p7.constraint.name=No Constraint\npolicyset.set1.p7.default.class_id=certificatePoliciesExtDefaultImpl\npolicyset.set1.p7.default.name=Certificate Policies Extension Default\npolicyset.set1.p7.default.params.Critical=false\npolicyset.set1.p7.default.params.PoliciesExt.num=5\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.enable=true\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p8.constraint.class_id=noConstraintImpl\npolicyset.set1.p8.constraint.name=No Constraint\npolicyset.set1.p8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.set1.p8.default.name=Subject Key Identifier Default\npolicyset.set1.p9.constraint.class_id=noConstraintImpl\npolicyset.set1.p9.constraint.name=No Constraint\npolicyset.set1.p9.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.set1.p9.default.name=Authority Key Identifier Extension Default\npolicyset.set1.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.set1.10.constraint.name=Renewal Grace Period Constraint\npolicyset.set1.10.constraint.params.renewal.graceBefore=30\npolicyset.set1.10.constraint.params.renewal.graceAfter=30\npolicyset.set1.10.default.class_id=noDefaultImpl\npolicyset.set1.10.default.name=No Default\npolicyset.set1.p12.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.set1.p12.constraint.name=Basic Constraints Extension Constraint\npolicyset.set1.p12.constraint.params.basicConstraintsCritical=-\npolicyset.set1.p12.constraint.params.basicConstraintsIsCA=-\npolicyset.set1.p12.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.set1.p12.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.set1.p12.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.set1.p12.default.name=Basic Constraints Extension Default\npolicyset.set1.p12.default.params.basicConstraintsCritical=false\npolicyset.set1.p12.default.params.basicConstraintsIsCA=false\npolicyset.set1.p12.default.params.basicConstraintsPathLen=-1\npolicyset.set1.p13.constraint.class_id=noConstraintImpl\npolicyset.set1.p13.constraint.name=No Constraint\npolicyset.set1.p13.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.name=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.params.crlDistPointsCritical=false\npolicyset.set1.p13.default.params.crlDistPointsNum=1\npolicyset.set1.p13.default.params.crlDistPointsEnable_0=false\npolicyset.set1.p13.default.params.crlDistPointsIssuerName_0=\npolicyset.set1.p13.default.params.crlDistPointsIssuerType_0=\npolicyset.set1.p13.default.params.crlDistPointsPointName_0=\npolicyset.set1.p13.default.params.crlDistPointsPointType_0=URIName\npolicyset.set1.p13.default.params.crlDistPointsReasons_0=\npolicyset.set1.p14.constraint.class_id=noConstraintImpl\npolicyset.set1.p14.constraint.name=No Constraint\npolicyset.set1.p14.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.set1.p14.default.name=AIA Extension Default\npolicyset.set1.p14.default.params.authInfoAccessADEnable_0=false\npolicyset.set1.p14.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.set1.p14.default.params.authInfoAccessADLocation_0=\npolicyset.set1.p14.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.set1.p14.default.params.authInfoAccessCritical=false\npolicyset.set1.p14.default.params.authInfoAccessNumADs=1\nprofileId=caTokenUserEncryptionKeyEnrollment\nclassId=caUserCertEnrollImpl\n' 2020-06-17T10:09:17Z DEBUG response status 409 2020-06-17T10:09:17Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:17Z DEBUG Error migrating 'caTokenUserEncryptionKeyEnrollment': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:17Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caTokenUserEncryptionKeyEnrollment?action=enable 2020-06-17T10:09:17Z DEBUG request body '' 2020-06-17T10:09:17Z DEBUG response status 409 2020-06-17T10:09:17Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:17Z DEBUG Failed to enable profile 'caTokenUserEncryptionKeyEnrollment' (it is probably already enabled) 2020-06-17T10:09:17Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:17Z DEBUG request body '' 2020-06-17T10:09:17Z DEBUG response status 204 2020-06-17T10:09:17Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=B7CDCEE1455B4388E349B9D448A9A16A; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'' 2020-06-17T10:09:17Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:17Z DEBUG request body '' 2020-06-17T10:09:17Z DEBUG response status 200 2020-06-17T10:09:17Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=6D7BBCCC66DF9A7E68B2127E505FAEF5; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:17Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:17Z DEBUG request body 'desc=This profile is for enrolling Token Signing key\nenable=true\nenableBy=admin\nname=Token User Signing Certificate Enrollment\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1\ninput.i1.class_id=nsNKeyCertReqInputImpl\ninput.i1.name=nsNKeyCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=nsNKeyOutputImpl\noutput.o2.name=nsNKeyOutputImpl\npolicyset.list=set1\n#policyset.set1.list=p2,p4,p5,p1,p6,p7,p8,p9,p12,p13,p14\npolicyset.set1.list=p2,p4,p5,p1,p6,p8,p9,p12\npolicyset.set1.p1.constraint.class_id=noConstraintImpl\npolicyset.set1.p1.constraint.name=No Constraint\npolicyset.set1.p1.default.class_id=nsTokenUserKeySubjectNameDefaultImpl\npolicyset.set1.p1.default.name=nsTokenUserKeySubjectNameDefault\npolicyset.set1.p1.default.params.dnpattern=UID=$request.uid$, O=Token Key User\n#changed ldap.enable to true to support SMIME\npolicyset.set1.p1.default.params.ldap.enable=false\npolicyset.set1.p1.default.params.ldap.searchName=uid\npolicyset.set1.p1.default.params.ldapStringAttributes=uid,mail\npolicyset.set1.p1.default.params.ldap.basedn=\npolicyset.set1.p1.default.params.ldap.maxConns=4\npolicyset.set1.p1.default.params.ldap.minConns=1\npolicyset.set1.p1.default.params.ldap.ldapconn.Version=2\npolicyset.set1.p1.default.params.ldap.ldapconn.host=\npolicyset.set1.p1.default.params.ldap.ldapconn.port=\npolicyset.set1.p1.default.params.ldap.ldapconn.secureConn=false\npolicyset.set1.p2.constraint.class_id=noConstraintImpl\npolicyset.set1.p2.constraint.name=No Constraint\npolicyset.set1.p2.default.class_id=validityDefaultImpl\npolicyset.set1.p2.default.name=Validity Default\npolicyset.set1.p2.default.params.range=1825\npolicyset.set1.p2.default.params.startTime=0\npolicyset.set1.p4.constraint.class_id=noConstraintImpl\npolicyset.set1.p4.constraint.name=No Constraint\npolicyset.set1.p4.default.class_id=signingAlgDefaultImpl\npolicyset.set1.p4.default.name=Signing Algorithm Default\npolicyset.set1.p4.default.params.signingAlg=-\npolicyset.set1.p5.constraint.class_id=noConstraintImpl\npolicyset.set1.p5.constraint.name=No Constraint\npolicyset.set1.p5.default.class_id=keyUsageExtDefaultImpl\npolicyset.set1.p5.default.name=Key Usage Extension Default\npolicyset.set1.p5.default.params.keyUsageCritical=true\npolicyset.set1.p5.default.params.keyUsageCrlSign=false\npolicyset.set1.p5.default.params.keyUsageDataEncipherment=false\npolicyset.set1.p5.default.params.keyUsageDecipherOnly=false\npolicyset.set1.p5.default.params.keyUsageDigitalSignature=true\npolicyset.set1.p5.default.params.keyUsageEncipherOnly=false\npolicyset.set1.p5.default.params.keyUsageKeyAgreement=false\npolicyset.set1.p5.default.params.keyUsageKeyCertSign=false\npolicyset.set1.p5.default.params.keyUsageKeyEncipherment=false\npolicyset.set1.p5.default.params.keyUsageNonRepudiation=true\npolicyset.set1.p6.constraint.class_id=noConstraintImpl\npolicyset.set1.p6.constraint.name=No Constraint\npolicyset.set1.p6.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.set1.p6.default.name=Subject Alternative Name Extension Default\npolicyset.set1.p6.default.params.subjAltExtGNEnable_0=true\npolicyset.set1.p6.default.params.subjAltExtGNEnable_1=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_2=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_3=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_4=false\npolicyset.set1.p6.default.params.subjAltExtPattern_0=$request.mail$\npolicyset.set1.p6.default.params.subjAltExtPattern_1=\npolicyset.set1.p6.default.params.subjAltExtPattern_2=\npolicyset.set1.p6.default.params.subjAltExtPattern_3=\npolicyset.set1.p6.default.params.subjAltExtPattern_4=\npolicyset.set1.p6.default.params.subjAltExtType_0=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_1=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_2=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_3=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_4=RFC822Name\npolicyset.set1.p6.default.params.subjAltNameExtCritical=false\npolicyset.set1.p6.default.params.subjAltNameNumGNs=1\npolicyset.set1.p7.constraint.class_id=noConstraintImpl\npolicyset.set1.p7.constraint.name=No Constraint\npolicyset.set1.p7.default.class_id=certificatePoliciesExtDefaultImpl\npolicyset.set1.p7.default.name=Certificate Policies Extension Default\npolicyset.set1.p7.default.params.Critical=false\npolicyset.set1.p7.default.params.PoliciesExt.num=5\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.enable=true\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p8.constraint.class_id=noConstraintImpl\npolicyset.set1.p8.constraint.name=No Constraint\npolicyset.set1.p8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.set1.p8.default.name=Subject Key Identifier Default\npolicyset.set1.p9.constraint.class_id=noConstraintImpl\npolicyset.set1.p9.constraint.name=No Constraint\npolicyset.set1.p9.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.set1.p9.default.name=Authority Key Identifier Extension Default\npolicyset.set1.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.set1.10.constraint.name=Renewal Grace Period Constraint\npolicyset.set1.10.constraint.params.renewal.graceBefore=30\npolicyset.set1.10.constraint.params.renewal.graceAfter=30\npolicyset.set1.10.default.class_id=noDefaultImpl\npolicyset.set1.10.default.name=No Default\npolicyset.set1.p12.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.set1.p12.constraint.name=Basic Constraints Extension Constraint\npolicyset.set1.p12.constraint.params.basicConstraintsCritical=-\npolicyset.set1.p12.constraint.params.basicConstraintsIsCA=-\npolicyset.set1.p12.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.set1.p12.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.set1.p12.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.set1.p12.default.name=Basic Constraints Extension Default\npolicyset.set1.p12.default.params.basicConstraintsCritical=false\npolicyset.set1.p12.default.params.basicConstraintsIsCA=false\npolicyset.set1.p12.default.params.basicConstraintsPathLen=-1\npolicyset.set1.p13.constraint.class_id=noConstraintImpl\npolicyset.set1.p13.constraint.name=No Constraint\npolicyset.set1.p13.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.name=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.params.crlDistPointsCritical=false\npolicyset.set1.p13.default.params.crlDistPointsNum=1\npolicyset.set1.p13.default.params.crlDistPointsEnable_0=false\npolicyset.set1.p13.default.params.crlDistPointsIssuerName_0=\npolicyset.set1.p13.default.params.crlDistPointsIssuerType_0=\npolicyset.set1.p13.default.params.crlDistPointsPointName_0=\npolicyset.set1.p13.default.params.crlDistPointsPointType_0=URIName\npolicyset.set1.p13.default.params.crlDistPointsReasons_0=\npolicyset.set1.p14.constraint.class_id=noConstraintImpl\npolicyset.set1.p14.constraint.name=No Constraint\npolicyset.set1.p14.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.set1.p14.default.name=AIA Extension Default\npolicyset.set1.p14.default.params.authInfoAccessADEnable_0=false\npolicyset.set1.p14.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.set1.p14.default.params.authInfoAccessADLocation_0=\npolicyset.set1.p14.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.set1.p14.default.params.authInfoAccessCritical=false\npolicyset.set1.p14.default.params.authInfoAccessNumADs=1\nprofileId=caTokenUserSigningKeyEnrollment\nclassId=caUserCertEnrollImpl\n' 2020-06-17T10:09:17Z DEBUG response status 409 2020-06-17T10:09:17Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:17Z DEBUG Error migrating 'caTokenUserSigningKeyEnrollment': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:17Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caTokenUserSigningKeyEnrollment?action=enable 2020-06-17T10:09:17Z DEBUG request body '' 2020-06-17T10:09:17Z DEBUG response status 409 2020-06-17T10:09:17Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:17Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:17Z DEBUG Failed to enable profile 'caTokenUserSigningKeyEnrollment' (it is probably already enabled) 2020-06-17T10:09:17Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:17Z DEBUG request body '' 2020-06-17T10:09:18Z DEBUG response status 204 2020-06-17T10:09:18Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=928E24B074B59E9F4C65FD48EE3CD7FF; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'' 2020-06-17T10:09:18Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:18Z DEBUG request body '' 2020-06-17T10:09:18Z DEBUG response status 200 2020-06-17T10:09:18Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=5C37206E64E4163C1FFBE78279497818; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:18Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:18Z DEBUG request body 'desc=This profile is for enrolling token device keys\nenable=true\nenableBy=admin\nlastModified=1068835451090\nname=Temporary Device Certificate Enrollment\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1\ninput.i1.class_id=nsHKeyCertReqInputImpl\ninput.i1.name=nsHKeyCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=nsNKeyOutputImpl\noutput.o2.name=nsNKeyOutputImpl\npolicyset.list=set1\n#policyset.set1.list=p2,p3,p4,p5,p1,p7,p8,p9,p12,p6\npolicyset.set1.list=p2,p4,p5,p1,p8,p9,p12\npolicyset.set1.p1.constraint.class_id=noConstraintImpl\npolicyset.set1.p1.constraint.name=No Constraint\npolicyset.set1.p1.default.class_id=nsTokenDeviceKeySubjectNameDefaultImpl\npolicyset.set1.p1.default.name=nsTokenDeviceKeySubjectNameDefault\npolicyset.set1.p1.default.params.dnpattern=UID=Token Key Device - $request.tokencuid$\npolicyset.set1.p12.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.set1.p12.constraint.name=Basic Constraints Extension Constraint\npolicyset.set1.p12.constraint.params.basicConstraintsCritical=-\npolicyset.set1.p12.constraint.params.basicConstraintsIsCA=-\npolicyset.set1.p12.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.set1.p12.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.set1.p12.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.set1.p12.default.name=Basic Constraints Extension Default\npolicyset.set1.p12.default.params.basicConstraintsCritical=false\npolicyset.set1.p12.default.params.basicConstraintsIsCA=false\npolicyset.set1.p12.default.params.basicConstraintsPathLen=-1\npolicyset.set1.p2.constraint.class_id=noConstraintImpl\npolicyset.set1.p2.constraint.name=No Constraint\npolicyset.set1.p2.default.class_id=validityDefaultImpl\npolicyset.set1.p2.default.name=Validity Default\npolicyset.set1.p2.default.params.range=7\npolicyset.set1.p2.default.params.startTime=0\npolicyset.set1.p3.constraint.class_id=noConstraintImpl\npolicyset.set1.p3.constraint.name=No Constraint\npolicyset.set1.p3.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p3.default.name=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p3.default.params.crlDistPointsCritical=false\npolicyset.set1.p3.default.params.crlDistPointsNum=1\npolicyset.set1.p3.default.params.crlDistPointsEnable_0=false\npolicyset.set1.p3.default.params.crlDistPointsIssuerName_0=\npolicyset.set1.p3.default.params.crlDistPointsIssuerType_0=\npolicyset.set1.p3.default.params.crlDistPointsPointName_0=\npolicyset.set1.p3.default.params.crlDistPointsPointType_0=URIName\npolicyset.set1.p3.default.params.crlDistPointsReasons_0=\npolicyset.set1.p4.constraint.class_id=noConstraintImpl\npolicyset.set1.p4.constraint.name=No Constraint\npolicyset.set1.p4.default.class_id=signingAlgDefaultImpl\npolicyset.set1.p4.default.name=Signing Algorithm Default\npolicyset.set1.p4.default.params.signingAlg=-\npolicyset.set1.p5.constraint.class_id=noConstraintImpl\npolicyset.set1.p5.constraint.name=No Constraint\npolicyset.set1.p5.default.class_id=keyUsageExtDefaultImpl\npolicyset.set1.p5.default.name=Key Usage Extension Default\npolicyset.set1.p5.default.params.keyUsageCritical=true\npolicyset.set1.p5.default.params.keyUsageCrlSign=false\npolicyset.set1.p5.default.params.keyUsageDataEncipherment=false\npolicyset.set1.p5.default.params.keyUsageDecipherOnly=false\npolicyset.set1.p5.default.params.keyUsageDigitalSignature=true\npolicyset.set1.p5.default.params.keyUsageEncipherOnly=false\npolicyset.set1.p5.default.params.keyUsageKeyAgreement=false\npolicyset.set1.p5.default.params.keyUsageKeyCertSign=false\npolicyset.set1.p5.default.params.keyUsageKeyEncipherment=false\npolicyset.set1.p5.default.params.keyUsageNonRepudiation=false\npolicyset.set1.p7.constraint.class_id=noConstraintImpl\npolicyset.set1.p7.constraint.name=No Constraint\npolicyset.set1.p7.default.class_id=certificatePoliciesExtDefaultImpl\npolicyset.set1.p7.default.name=Certificate Policies Extension Default\npolicyset.set1.p7.default.params.Critical=false\npolicyset.set1.p7.default.params.PoliciesExt.num=5\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p8.constraint.class_id=noConstraintImpl\npolicyset.set1.p8.constraint.name=No Constraint\npolicyset.set1.p8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.set1.p8.default.name=Subject Key Identifier Default\npolicyset.set1.p9.constraint.class_id=noConstraintImpl\npolicyset.set1.p9.constraint.name=No Constraint\npolicyset.set1.p9.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.set1.p9.default.name=Authority Key Identifier Extension Default\npolicyset.set1.p6.constraint.class_id=noConstraintImpl\npolicyset.set1.p6.constraint.name=No Constraint\npolicyset.set1.p6.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.set1.p6.default.name=Subject Alternative Name Extension Default\npolicyset.set1.p6.default.params.subjAltExtGNEnable_0=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_1=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_2=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_3=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_4=false\npolicyset.set1.p6.default.params.subjAltExtPattern_0=\npolicyset.set1.p6.default.params.subjAltExtPattern_1=\npolicyset.set1.p6.default.params.subjAltExtPattern_2=\npolicyset.set1.p6.default.params.subjAltExtPattern_3=\npolicyset.set1.p6.default.params.subjAltExtPattern_4=\npolicyset.set1.p6.default.params.subjAltExtType_0=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_1=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_2=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_3=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_4=RFC822Name\npolicyset.set1.p6.default.params.subjAltNameExtCritical=false\npolicyset.set1.p6.default.params.subjAltNameNumGNs=1\nprofileId=caTempTokenDeviceKeyEnrollment\nclassId=caUserCertEnrollImpl\n' 2020-06-17T10:09:18Z DEBUG response status 409 2020-06-17T10:09:18Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:18Z DEBUG Error migrating 'caTempTokenDeviceKeyEnrollment': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:18Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caTempTokenDeviceKeyEnrollment?action=enable 2020-06-17T10:09:18Z DEBUG request body '' 2020-06-17T10:09:18Z DEBUG response status 409 2020-06-17T10:09:18Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:18Z DEBUG Failed to enable profile 'caTempTokenDeviceKeyEnrollment' (it is probably already enabled) 2020-06-17T10:09:18Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:18Z DEBUG request body '' 2020-06-17T10:09:18Z DEBUG response status 204 2020-06-17T10:09:18Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=9B7D73EC2B860D37A93053A1A2E614A1; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'' 2020-06-17T10:09:18Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:18Z DEBUG request body '' 2020-06-17T10:09:18Z DEBUG response status 200 2020-06-17T10:09:18Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=50A4696A1A7935B8B0534354566034D8; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:18Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:18Z DEBUG request body 'desc=This profile is for enrolling Token Encryption key\nenable=true\nenableBy=admin\nname=Temporary Token User Encryption Certificate Enrollment\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1\ninput.i1.class_id=nsNKeyCertReqInputImpl\ninput.i1.name=nsNKeyCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=nsNKeyOutputImpl\noutput.o2.name=nsNKeyOutputImpl\npolicyset.list=set1\n#policyset.set1.list=p2,p4,p5,p1,p6,p7,p8,p9,p12,p13,p14\npolicyset.set1.list=p2,p4,p5,p1,p6,p8,p9,p12\npolicyset.set1.p1.constraint.class_id=noConstraintImpl\npolicyset.set1.p1.constraint.name=No Constraint\npolicyset.set1.p1.default.class_id=nsTokenUserKeySubjectNameDefaultImpl\npolicyset.set1.p1.default.name=nsTokenUserKeySubjectNameDefault\n#uncomment below to support SMIME\n#policyset.set1.p1.default.params.dnpattern=UID=$request.uid$, E=$request.mail$, O=Token Key User\npolicyset.set1.p1.default.params.dnpattern=UID=$request.uid$, O=Token Key User\n#changed ldap.enable to true to support SMIME\npolicyset.set1.p1.default.params.ldap.enable=false\npolicyset.set1.p1.default.params.ldap.searchName=uid\npolicyset.set1.p1.default.params.ldapStringAttributes=uid,mail\npolicyset.set1.p1.default.params.ldap.basedn=\npolicyset.set1.p1.default.params.ldap.maxConns=4\npolicyset.set1.p1.default.params.ldap.minConns=1\npolicyset.set1.p1.default.params.ldap.ldapconn.Version=2\npolicyset.set1.p1.default.params.ldap.ldapconn.host=\npolicyset.set1.p1.default.params.ldap.ldapconn.port=\npolicyset.set1.p1.default.params.ldap.ldapconn.secureConn=false\npolicyset.set1.p2.constraint.class_id=noConstraintImpl\npolicyset.set1.p2.constraint.name=No Constraint\npolicyset.set1.p2.default.class_id=validityDefaultImpl\npolicyset.set1.p2.default.name=Validity Default\npolicyset.set1.p2.default.params.range=7\npolicyset.set1.p2.default.params.startTime=0\npolicyset.set1.p4.constraint.class_id=noConstraintImpl\npolicyset.set1.p4.constraint.name=No Constraint\npolicyset.set1.p4.default.class_id=signingAlgDefaultImpl\npolicyset.set1.p4.default.name=Signing Algorithm Default\npolicyset.set1.p4.default.params.signingAlg=-\npolicyset.set1.p5.constraint.class_id=noConstraintImpl\npolicyset.set1.p5.constraint.name=No Constraint\npolicyset.set1.p5.default.class_id=keyUsageExtDefaultImpl\npolicyset.set1.p5.default.name=Key Usage Extension Default\npolicyset.set1.p5.default.params.keyUsageCritical=true\npolicyset.set1.p5.default.params.keyUsageCrlSign=false\npolicyset.set1.p5.default.params.keyUsageDataEncipherment=false\npolicyset.set1.p5.default.params.keyUsageDecipherOnly=false\npolicyset.set1.p5.default.params.keyUsageDigitalSignature=false\npolicyset.set1.p5.default.params.keyUsageEncipherOnly=false\npolicyset.set1.p5.default.params.keyUsageKeyAgreement=false\npolicyset.set1.p5.default.params.keyUsageKeyCertSign=false\npolicyset.set1.p5.default.params.keyUsageKeyEncipherment=true\npolicyset.set1.p5.default.params.keyUsageNonRepudiation=false\npolicyset.set1.p6.constraint.class_id=noConstraintImpl\npolicyset.set1.p6.constraint.name=No Constraint\npolicyset.set1.p6.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.set1.p6.default.name=Subject Alternative Name Extension Default\npolicyset.set1.p6.default.params.subjAltExtGNEnable_0=true\npolicyset.set1.p6.default.params.subjAltExtGNEnable_1=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_2=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_3=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_4=false\npolicyset.set1.p6.default.params.subjAltExtPattern_0=$request.mail$\npolicyset.set1.p6.default.params.subjAltExtPattern_1=\npolicyset.set1.p6.default.params.subjAltExtPattern_2=\npolicyset.set1.p6.default.params.subjAltExtPattern_3=\npolicyset.set1.p6.default.params.subjAltExtPattern_4=\npolicyset.set1.p6.default.params.subjAltExtType_0=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_1=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_2=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_3=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_4=RFC822Name\npolicyset.set1.p6.default.params.subjAltNameExtCritical=false\npolicyset.set1.p6.default.params.subjAltNameNumGNs=1\npolicyset.set1.p7.constraint.class_id=noConstraintImpl\npolicyset.set1.p7.constraint.name=No Constraint\npolicyset.set1.p7.default.class_id=certificatePoliciesExtDefaultImpl\npolicyset.set1.p7.default.name=Certificate Policies Extension Default\npolicyset.set1.p7.default.params.Critical=false\npolicyset.set1.p7.default.params.PoliciesExt.num=5\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.enable=true\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p8.constraint.class_id=noConstraintImpl\npolicyset.set1.p8.constraint.name=No Constraint\npolicyset.set1.p8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.set1.p8.default.name=Subject Key Identifier Default\npolicyset.set1.p9.constraint.class_id=noConstraintImpl\npolicyset.set1.p9.constraint.name=No Constraint\npolicyset.set1.p9.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.set1.p9.default.name=Authority Key Identifier Extension Default\npolicyset.set1.p12.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.set1.p12.constraint.name=Basic Constraints Extension Constraint\npolicyset.set1.p12.constraint.params.basicConstraintsCritical=-\npolicyset.set1.p12.constraint.params.basicConstraintsIsCA=-\npolicyset.set1.p12.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.set1.p12.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.set1.p12.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.set1.p12.default.name=Basic Constraints Extension Default\npolicyset.set1.p12.default.params.basicConstraintsCritical=false\npolicyset.set1.p12.default.params.basicConstraintsIsCA=false\npolicyset.set1.p12.default.params.basicConstraintsPathLen=-1\npolicyset.set1.p13.constraint.class_id=noConstraintImpl\npolicyset.set1.p13.constraint.name=No Constraint\npolicyset.set1.p13.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.name=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.params.crlDistPointsCritical=false\npolicyset.set1.p13.default.params.crlDistPointsNum=1\npolicyset.set1.p13.default.params.crlDistPointsEnable_0=false\npolicyset.set1.p13.default.params.crlDistPointsIssuerName_0=\npolicyset.set1.p13.default.params.crlDistPointsIssuerType_0=\npolicyset.set1.p13.default.params.crlDistPointsPointName_0=\npolicyset.set1.p13.default.params.crlDistPointsPointType_0=URIName\npolicyset.set1.p13.default.params.crlDistPointsReasons_0=\npolicyset.set1.p14.constraint.class_id=noConstraintImpl\npolicyset.set1.p14.constraint.name=No Constraint\npolicyset.set1.p14.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.set1.p14.default.name=AIA Extension Default\npolicyset.set1.p14.default.params.authInfoAccessADEnable_0=false\npolicyset.set1.p14.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.set1.p14.default.params.authInfoAccessADLocation_0=\npolicyset.set1.p14.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.set1.p14.default.params.authInfoAccessCritical=false\npolicyset.set1.p14.default.params.authInfoAccessNumADs=1\nprofileId=caTempTokenUserEncryptionKeyEnrollment\nclassId=caUserCertEnrollImpl\n' 2020-06-17T10:09:18Z DEBUG response status 409 2020-06-17T10:09:18Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:18Z DEBUG Error migrating 'caTempTokenUserEncryptionKeyEnrollment': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:18Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caTempTokenUserEncryptionKeyEnrollment?action=enable 2020-06-17T10:09:18Z DEBUG request body '' 2020-06-17T10:09:18Z DEBUG response status 409 2020-06-17T10:09:18Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:18Z DEBUG Failed to enable profile 'caTempTokenUserEncryptionKeyEnrollment' (it is probably already enabled) 2020-06-17T10:09:18Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:18Z DEBUG request body '' 2020-06-17T10:09:18Z DEBUG response status 204 2020-06-17T10:09:18Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=1F739FB2317573BF555B77428DB6CC8D; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'' 2020-06-17T10:09:18Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:18Z DEBUG request body '' 2020-06-17T10:09:18Z DEBUG response status 200 2020-06-17T10:09:18Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=AA6DFFF057A15A1CAFB573A184A52490; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:17 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:18Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:18Z DEBUG request body 'desc=This profile is for enrolling Token Signing key\nenable=true\nenableBy=admin\nname=Temporary Token User Signing Certificate Enrollment\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1\ninput.i1.class_id=nsNKeyCertReqInputImpl\ninput.i1.name=nsNKeyCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=nsNKeyOutputImpl\noutput.o2.name=nsNKeyOutputImpl\npolicyset.list=set1\n#policyset.set1.list=p2,p4,p5,p1,p6,p7,p8,p9,p12,p13,p14\npolicyset.set1.list=p2,p4,p5,p1,p6,p8,p9,p12\npolicyset.set1.p1.constraint.class_id=noConstraintImpl\npolicyset.set1.p1.constraint.name=No Constraint\npolicyset.set1.p1.default.class_id=nsTokenUserKeySubjectNameDefaultImpl\npolicyset.set1.p1.default.name=nsTokenUserKeySubjectNameDefault\n#uncomment below to support SMIME\n#policyset.set1.p1.default.params.dnpattern=UID=$request.uid$, E=$request.mail$, O=Token Key User\npolicyset.set1.p1.default.params.dnpattern=UID=$request.uid$, O=Token Key User\n#changed ldap.enable to true to support SMIME\npolicyset.set1.p1.default.params.ldap.enable=false\npolicyset.set1.p1.default.params.ldap.searchName=uid\npolicyset.set1.p1.default.params.ldapStringAttributes=uid,mail\npolicyset.set1.p1.default.params.ldap.basedn=\npolicyset.set1.p1.default.params.ldap.maxConns=4\npolicyset.set1.p1.default.params.ldap.minConns=1\npolicyset.set1.p1.default.params.ldap.ldapconn.Version=2\npolicyset.set1.p1.default.params.ldap.ldapconn.host=\npolicyset.set1.p1.default.params.ldap.ldapconn.port=\npolicyset.set1.p1.default.params.ldap.ldapconn.secureConn=false\npolicyset.set1.p2.constraint.class_id=noConstraintImpl\npolicyset.set1.p2.constraint.name=No Constraint\npolicyset.set1.p2.default.class_id=validityDefaultImpl\npolicyset.set1.p2.default.name=Validity Default\npolicyset.set1.p2.default.params.range=7\npolicyset.set1.p2.default.params.startTime=0\npolicyset.set1.p4.constraint.class_id=noConstraintImpl\npolicyset.set1.p4.constraint.name=No Constraint\npolicyset.set1.p4.default.class_id=signingAlgDefaultImpl\npolicyset.set1.p4.default.name=Signing Algorithm Default\npolicyset.set1.p4.default.params.signingAlg=-\npolicyset.set1.p5.constraint.class_id=noConstraintImpl\npolicyset.set1.p5.constraint.name=No Constraint\npolicyset.set1.p5.default.class_id=keyUsageExtDefaultImpl\npolicyset.set1.p5.default.name=Key Usage Extension Default\npolicyset.set1.p5.default.params.keyUsageCritical=true\npolicyset.set1.p5.default.params.keyUsageCrlSign=false\npolicyset.set1.p5.default.params.keyUsageDataEncipherment=false\npolicyset.set1.p5.default.params.keyUsageDecipherOnly=false\npolicyset.set1.p5.default.params.keyUsageDigitalSignature=true\npolicyset.set1.p5.default.params.keyUsageEncipherOnly=false\npolicyset.set1.p5.default.params.keyUsageKeyAgreement=false\npolicyset.set1.p5.default.params.keyUsageKeyCertSign=false\npolicyset.set1.p5.default.params.keyUsageKeyEncipherment=false\npolicyset.set1.p5.default.params.keyUsageNonRepudiation=true\npolicyset.set1.p6.constraint.class_id=noConstraintImpl\npolicyset.set1.p6.constraint.name=No Constraint\npolicyset.set1.p6.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.set1.p6.default.name=Subject Alternative Name Extension Default\npolicyset.set1.p6.default.params.subjAltExtGNEnable_0=true\npolicyset.set1.p6.default.params.subjAltExtGNEnable_1=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_2=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_3=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_4=false\npolicyset.set1.p6.default.params.subjAltExtPattern_0=$request.mail$\npolicyset.set1.p6.default.params.subjAltExtPattern_1=\npolicyset.set1.p6.default.params.subjAltExtPattern_2=\npolicyset.set1.p6.default.params.subjAltExtPattern_3=\npolicyset.set1.p6.default.params.subjAltExtPattern_4=\npolicyset.set1.p6.default.params.subjAltExtType_0=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_1=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_2=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_3=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_4=RFC822Name\npolicyset.set1.p6.default.params.subjAltNameExtCritical=false\npolicyset.set1.p6.default.params.subjAltNameNumGNs=1\npolicyset.set1.p7.constraint.class_id=noConstraintImpl\npolicyset.set1.p7.constraint.name=No Constraint\npolicyset.set1.p7.default.class_id=certificatePoliciesExtDefaultImpl\npolicyset.set1.p7.default.name=Certificate Policies Extension Default\npolicyset.set1.p7.default.params.Critical=false\npolicyset.set1.p7.default.params.PoliciesExt.num=5\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.enable=true\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p8.constraint.class_id=noConstraintImpl\npolicyset.set1.p8.constraint.name=No Constraint\npolicyset.set1.p8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.set1.p8.default.name=Subject Key Identifier Default\npolicyset.set1.p9.constraint.class_id=noConstraintImpl\npolicyset.set1.p9.constraint.name=No Constraint\npolicyset.set1.p9.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.set1.p9.default.name=Authority Key Identifier Extension Default\npolicyset.set1.p12.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.set1.p12.constraint.name=Basic Constraints Extension Constraint\npolicyset.set1.p12.constraint.params.basicConstraintsCritical=-\npolicyset.set1.p12.constraint.params.basicConstraintsIsCA=-\npolicyset.set1.p12.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.set1.p12.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.set1.p12.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.set1.p12.default.name=Basic Constraints Extension Default\npolicyset.set1.p12.default.params.basicConstraintsCritical=false\npolicyset.set1.p12.default.params.basicConstraintsIsCA=false\npolicyset.set1.p12.default.params.basicConstraintsPathLen=-1\npolicyset.set1.p13.constraint.class_id=noConstraintImpl\npolicyset.set1.p13.constraint.name=No Constraint\npolicyset.set1.p13.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.name=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.params.crlDistPointsCritical=false\npolicyset.set1.p13.default.params.crlDistPointsNum=1\npolicyset.set1.p13.default.params.crlDistPointsEnable_0=false\npolicyset.set1.p13.default.params.crlDistPointsIssuerName_0=\npolicyset.set1.p13.default.params.crlDistPointsIssuerType_0=\npolicyset.set1.p13.default.params.crlDistPointsPointName_0=\npolicyset.set1.p13.default.params.crlDistPointsPointType_0=URIName\npolicyset.set1.p13.default.params.crlDistPointsReasons_0=\npolicyset.set1.p14.constraint.class_id=noConstraintImpl\npolicyset.set1.p14.constraint.name=No Constraint\npolicyset.set1.p14.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.set1.p14.default.name=AIA Extension Default\npolicyset.set1.p14.default.params.authInfoAccessADEnable_0=false\npolicyset.set1.p14.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.set1.p14.default.params.authInfoAccessADLocation_0=\npolicyset.set1.p14.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.set1.p14.default.params.authInfoAccessCritical=false\npolicyset.set1.p14.default.params.authInfoAccessNumADs=1\nprofileId=caTempTokenUserSigningKeyEnrollment\nclassId=caUserCertEnrollImpl\n' 2020-06-17T10:09:18Z DEBUG response status 409 2020-06-17T10:09:18Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:18Z DEBUG Error migrating 'caTempTokenUserSigningKeyEnrollment': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:18Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caTempTokenUserSigningKeyEnrollment?action=enable 2020-06-17T10:09:18Z DEBUG request body '' 2020-06-17T10:09:18Z DEBUG response status 409 2020-06-17T10:09:18Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:18Z DEBUG Failed to enable profile 'caTempTokenUserSigningKeyEnrollment' (it is probably already enabled) 2020-06-17T10:09:18Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:18Z DEBUG request body '' 2020-06-17T10:09:18Z DEBUG response status 204 2020-06-17T10:09:18Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=50D38F3385F2539D1E6685AC9F679ED6; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'' 2020-06-17T10:09:18Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:18Z DEBUG request body '' 2020-06-17T10:09:18Z DEBUG response status 200 2020-06-17T10:09:18Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=BEED39C49333CFEA90AB49B7F62765F5; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:18Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:18Z DEBUG request body 'desc=This certificate profile is for enrolling Security Domain administrator\'s certificates with LDAP authentication against the internal LDAP database.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise RA Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Security Domain Administrator Certificate Enrollment\ninput.list=i1,i2,i3\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\ninput.i3.class_id=subjectDNInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=adminCertSet\npolicyset.adminCertSet.list=1,2,3,4,5,6,7,8\npolicyset.adminCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.adminCertSet.1.constraint.name=Subject Name Constraint\npolicyset.adminCertSet.1.constraint.params.pattern=.*\npolicyset.adminCertSet.1.constraint.params.accept=true\npolicyset.adminCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.adminCertSet.1.default.name=Subject Name Default\npolicyset.adminCertSet.1.default.params.name=\npolicyset.adminCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.adminCertSet.2.constraint.name=Validity Constraint\npolicyset.adminCertSet.2.constraint.params.range=365\npolicyset.adminCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.adminCertSet.2.constraint.params.notAfterCheck=false\npolicyset.adminCertSet.2.default.class_id=validityDefaultImpl\npolicyset.adminCertSet.2.default.name=Validity Default\npolicyset.adminCertSet.2.default.params.range=365\npolicyset.adminCertSet.2.default.params.startTime=0\npolicyset.adminCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.adminCertSet.3.constraint.name=Key Constraint\npolicyset.adminCertSet.3.constraint.params.keyType=RSA\npolicyset.adminCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.adminCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.adminCertSet.3.default.name=Key Default\npolicyset.adminCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.4.constraint.name=No Constraint\npolicyset.adminCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.adminCertSet.4.default.name=Authority Key Identifier Default\npolicyset.adminCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.5.constraint.name=No Constraint\npolicyset.adminCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.adminCertSet.5.default.name=AIA Extension Default\npolicyset.adminCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.adminCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.adminCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.adminCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.adminCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.adminCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.adminCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.adminCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.adminCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.adminCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.adminCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.adminCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.adminCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.adminCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.adminCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.adminCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.adminCertSet.6.default.name=Key Usage Default\npolicyset.adminCertSet.6.default.params.keyUsageCritical=true\npolicyset.adminCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.adminCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.adminCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.adminCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.adminCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.adminCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.adminCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.adminCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.adminCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.adminCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.7.constraint.name=No Constraint\npolicyset.adminCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.adminCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.adminCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.adminCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.adminCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.adminCertSet.8.constraint.name=No Constraint\npolicyset.adminCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.adminCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.adminCertSet.8.default.name=Signing Alg\npolicyset.adminCertSet.8.default.params.signingAlg=-\nprofileId=caAdminCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:18Z DEBUG response status 409 2020-06-17T10:09:18Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:18Z DEBUG Error migrating 'caAdminCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:18Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caAdminCert?action=enable 2020-06-17T10:09:18Z DEBUG request body '' 2020-06-17T10:09:18Z DEBUG response status 409 2020-06-17T10:09:18Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:18Z DEBUG Failed to enable profile 'caAdminCert' (it is probably already enabled) 2020-06-17T10:09:18Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:18Z DEBUG request body '' 2020-06-17T10:09:18Z DEBUG response status 204 2020-06-17T10:09:18Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=6B83BE890614BB8C76BAC25A230BB8C7; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'' 2020-06-17T10:09:18Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:18Z DEBUG request body '' 2020-06-17T10:09:18Z DEBUG response status 200 2020-06-17T10:09:18Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=B2D8EEC779B2566A7338C717D3C87AB6; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:18Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:18Z DEBUG request body 'desc=This certificate profile is for enrolling Security Domain administrator\'s certificates with ECC keys using LDAP authentication against the internal LDAP database.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise RA Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Security Domain Administrator Certificate Enrollment with ECC keys\ninput.list=i1,i2,i3\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\ninput.i3.class_id=subjectDNInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=adminCertSet\npolicyset.adminCertSet.list=1,2,3,4,5,6,7,8\npolicyset.adminCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.adminCertSet.1.constraint.name=Subject Name Constraint\npolicyset.adminCertSet.1.constraint.params.pattern=.*\npolicyset.adminCertSet.1.constraint.params.accept=true\npolicyset.adminCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.adminCertSet.1.default.name=Subject Name Default\npolicyset.adminCertSet.1.default.params.name=\npolicyset.adminCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.adminCertSet.2.constraint.name=Validity Constraint\npolicyset.adminCertSet.2.constraint.params.range=365\npolicyset.adminCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.adminCertSet.2.constraint.params.notAfterCheck=false\npolicyset.adminCertSet.2.default.class_id=validityDefaultImpl\npolicyset.adminCertSet.2.default.name=Validity Default\npolicyset.adminCertSet.2.default.params.range=365\npolicyset.adminCertSet.2.default.params.startTime=0\npolicyset.adminCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.adminCertSet.3.constraint.name=Key Constraint\npolicyset.adminCertSet.3.constraint.params.keyType=-\npolicyset.adminCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.adminCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.adminCertSet.3.default.name=Key Default\npolicyset.adminCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.4.constraint.name=No Constraint\npolicyset.adminCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.adminCertSet.4.default.name=Authority Key Identifier Default\npolicyset.adminCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.5.constraint.name=No Constraint\npolicyset.adminCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.adminCertSet.5.default.name=AIA Extension Default\npolicyset.adminCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.adminCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.adminCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.adminCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.adminCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.adminCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.adminCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.adminCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.adminCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.adminCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.adminCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.adminCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.adminCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.adminCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.adminCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.adminCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.adminCertSet.6.default.name=Key Usage Default\npolicyset.adminCertSet.6.default.params.keyUsageCritical=true\npolicyset.adminCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.adminCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.adminCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.adminCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.adminCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.adminCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.adminCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.adminCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.adminCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.adminCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.7.constraint.name=No Constraint\npolicyset.adminCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.adminCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.adminCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.adminCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.adminCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.adminCertSet.8.constraint.name=No Constraint\npolicyset.adminCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.adminCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.adminCertSet.8.default.name=Signing Alg\npolicyset.adminCertSet.8.default.params.signingAlg=-\nprofileId=caECAdminCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:18Z DEBUG response status 409 2020-06-17T10:09:18Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:18Z DEBUG Error migrating 'caECAdminCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:18Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caECAdminCert?action=enable 2020-06-17T10:09:18Z DEBUG request body '' 2020-06-17T10:09:18Z DEBUG response status 409 2020-06-17T10:09:18Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:18Z DEBUG Failed to enable profile 'caECAdminCert' (it is probably already enabled) 2020-06-17T10:09:18Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:18Z DEBUG request body '' 2020-06-17T10:09:18Z DEBUG response status 204 2020-06-17T10:09:18Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=322B06F508170FD0F8CA6E27BEC585E2; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'' 2020-06-17T10:09:18Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:18Z DEBUG request body '' 2020-06-17T10:09:18Z DEBUG response status 200 2020-06-17T10:09:18Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=235751A8018CAEF8BEB40C2C4131E7DE; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:18Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:18Z DEBUG request body 'desc=This certificate profile is for enrolling Security Domain server certificates.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise RA Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Security Domain Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\ninput.i3.class_id=subjectAltNameExtInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\n# allows SAN to be specified from client side\n# need to:\n# 1. add i3 to input.list above\n# 2. add 9 to policyset.serverCertSet.list above\n# 3. change below to reflect the number of general names, and\n# turn each corresponding subjAltExtPattern_ to true\n# policyset.serverCertSet.9.default.params.subjAltNameNumGNs\n#\n# If the subjectAltNameExtDefaultImpl is on, then commonNameToSANDefault\n# would "merge" into existing SAN. Keep commonNameToSANDefault as last entry\n#\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.serverCertSet.9.default.name=Subject Alternative Name Extension Default\npolicyset.serverCertSet.9.default.params.subjAltExtGNEnable_0=true\npolicyset.serverCertSet.9.default.params.subjAltExtPattern_0=$request.req_san_pattern_0$\npolicyset.serverCertSet.9.default.params.subjAltExtType_0=DNSName\npolicyset.serverCertSet.9.default.params.subjAltExtGNEnable_1=false\npolicyset.serverCertSet.9.default.params.subjAltExtPattern_1=$request.req_san_pattern_1$\npolicyset.serverCertSet.9.default.params.subjAltExtType_1=DNSName\npolicyset.serverCertSet.9.default.params.subjAltExtGNEnable_2=false\npolicyset.serverCertSet.9.default.params.subjAltExtPattern_2=$request.req_san_pattern_2$\npolicyset.serverCertSet.9.default.params.subjAltExtType_2=DNSName\npolicyset.serverCertSet.9.default.params.subjAltNameExtCritical=false\npolicyset.serverCertSet.9.default.params.subjAltNameNumGNs=1\n#\n# While the subjectAltNameExtDefaultImpl above allows multiple SANs to be\n# specified during installation, the commonNameToSANDefaultImpl adds a simple\n# default single SAN from CN.\n#\n# If the subjectAltNameExtDefaultImpl is on, then commonNameToSANDefault\n# would "merge" into existing SAN. Keep commonNameToSANDefault as last entry\n#\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name Extension\nprofileId=caInternalAuthServerCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:18Z DEBUG response status 409 2020-06-17T10:09:18Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:18Z DEBUG Error migrating 'caInternalAuthServerCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:18Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caInternalAuthServerCert?action=enable 2020-06-17T10:09:18Z DEBUG request body '' 2020-06-17T10:09:18Z DEBUG response status 409 2020-06-17T10:09:18Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:18Z DEBUG Failed to enable profile 'caInternalAuthServerCert' (it is probably already enabled) 2020-06-17T10:09:18Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:18Z DEBUG request body '' 2020-06-17T10:09:18Z DEBUG response status 204 2020-06-17T10:09:18Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=CC0E978BDDC5300FD4E62B6FC48EE31B; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'' 2020-06-17T10:09:18Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:18Z DEBUG request body '' 2020-06-17T10:09:18Z DEBUG response status 200 2020-06-17T10:09:18Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=66D285CC983945AAF16EC34AF70954D2; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:18Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:18Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:18Z DEBUG request body 'desc=This certificate profile is for enrolling Security Domain ECC server certificates.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise RA Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Security Domain Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\ninput.i3.class_id=subjectAltNameExtInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=-\npolicyset.serverCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\n# allows SAN to be specified from client side\n# need to:\n# 1. add i3 to input.list above\n# 2. add 9 to policyset.serverCertSet.list above\n# 3. change below to reflect the number of general names, and\n# turn each corresponding subjAltExtPattern_ to true\n# policyset.serverCertSet.9.default.params.subjAltNameNumGNs\n#\n# If the subjectAltNameExtDefaultImpl is on, then commonNameToSANDefault\n# would "merge" into existing SAN. Keep commonNameToSANDefault as last entry\n#\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.serverCertSet.9.default.name=Subject Alternative Name Extension Default\npolicyset.serverCertSet.9.default.params.subjAltExtGNEnable_0=true\npolicyset.serverCertSet.9.default.params.subjAltExtPattern_0=$request.req_san_pattern_0$\npolicyset.serverCertSet.9.default.params.subjAltExtType_0=DNSName\npolicyset.serverCertSet.9.default.params.subjAltExtGNEnable_1=false\npolicyset.serverCertSet.9.default.params.subjAltExtPattern_1=$request.req_san_pattern_1$\npolicyset.serverCertSet.9.default.params.subjAltExtType_1=DNSName\npolicyset.serverCertSet.9.default.params.subjAltExtGNEnable_2=false\npolicyset.serverCertSet.9.default.params.subjAltExtPattern_2=$request.req_san_pattern_2$\npolicyset.serverCertSet.9.default.params.subjAltExtType_2=DNSName\npolicyset.serverCertSet.9.default.params.subjAltNameExtCritical=false\npolicyset.serverCertSet.9.default.params.subjAltNameNumGNs=1\n#\n# While the subjectAltNameExtDefaultImpl above allows multiple SANs to be\n# specified during installation, the commonNameToSANDefaultImpl adds a simple\n# default single SAN from CN.\n#\n# If the subjectAltNameExtDefaultImpl is on, then commonNameToSANDefault\n# would "merge" into existing SAN. Keep commonNameToSANDefault as last entry\n#\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name Extension\nprofileId=caECInternalAuthServerCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:19Z DEBUG response status 409 2020-06-17T10:09:19Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:19Z DEBUG Error migrating 'caECInternalAuthServerCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:19Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caECInternalAuthServerCert?action=enable 2020-06-17T10:09:19Z DEBUG request body '' 2020-06-17T10:09:19Z DEBUG response status 409 2020-06-17T10:09:19Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:19Z DEBUG Failed to enable profile 'caECInternalAuthServerCert' (it is probably already enabled) 2020-06-17T10:09:19Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:19Z DEBUG request body '' 2020-06-17T10:09:19Z DEBUG response status 204 2020-06-17T10:09:19Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=7A956D4A07CC744EB3D181265E6CCE94; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'' 2020-06-17T10:09:19Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:19Z DEBUG request body '' 2020-06-17T10:09:19Z DEBUG response status 200 2020-06-17T10:09:19Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=C7A9299DEF43A035C58D4426D015C204; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:19Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:19Z DEBUG request body 'desc=This certificate profile is for enrolling Security Domain Data Recovery Manager transport certificates.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise RA Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Security Domain Data Recovery Manager Transport Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=transportCertSet\npolicyset.transportCertSet.list=1,2,3,4,5,6,7,8\npolicyset.transportCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.transportCertSet.1.constraint.name=Subject Name Constraint\npolicyset.transportCertSet.1.constraint.params.pattern=CN=.*\npolicyset.transportCertSet.1.constraint.params.accept=true\npolicyset.transportCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.transportCertSet.1.default.name=Subject Name Default\npolicyset.transportCertSet.1.default.params.name=\npolicyset.transportCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.transportCertSet.2.constraint.name=Validity Constraint\npolicyset.transportCertSet.2.constraint.params.range=720\npolicyset.transportCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.transportCertSet.2.constraint.params.notAfterCheck=false\npolicyset.transportCertSet.2.default.class_id=validityDefaultImpl\npolicyset.transportCertSet.2.default.name=Validity Default\npolicyset.transportCertSet.2.default.params.range=720\npolicyset.transportCertSet.2.default.params.startTime=0\npolicyset.transportCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.transportCertSet.3.constraint.name=Key Constraint\npolicyset.transportCertSet.3.constraint.params.keyType=-\npolicyset.transportCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.transportCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.transportCertSet.3.default.name=Key Default\npolicyset.transportCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.transportCertSet.4.constraint.name=No Constraint\npolicyset.transportCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.transportCertSet.4.default.name=Authority Key Identifier Default\npolicyset.transportCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.transportCertSet.5.constraint.name=No Constraint\npolicyset.transportCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.transportCertSet.5.default.name=AIA Extension Default\npolicyset.transportCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.transportCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.transportCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.transportCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.transportCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.transportCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.transportCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.transportCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.transportCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.transportCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.transportCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.transportCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.transportCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.transportCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.transportCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.transportCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.transportCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.transportCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.transportCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.transportCertSet.6.default.name=Key Usage Default\npolicyset.transportCertSet.6.default.params.keyUsageCritical=true\npolicyset.transportCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.transportCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.transportCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.transportCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.transportCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.transportCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.transportCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.transportCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.transportCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.transportCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.transportCertSet.7.constraint.name=No Constraint\npolicyset.transportCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.transportCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.transportCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.transportCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.transportCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.transportCertSet.8.constraint.name=No Constraint\npolicyset.transportCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.transportCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.transportCertSet.8.default.name=Signing Alg\npolicyset.transportCertSet.8.default.params.signingAlg=-\nprofileId=caInternalAuthTransportCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:19Z DEBUG response status 409 2020-06-17T10:09:19Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:19Z DEBUG Error migrating 'caInternalAuthTransportCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:19Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caInternalAuthTransportCert?action=enable 2020-06-17T10:09:19Z DEBUG request body '' 2020-06-17T10:09:19Z DEBUG response status 409 2020-06-17T10:09:19Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:19Z DEBUG Failed to enable profile 'caInternalAuthTransportCert' (it is probably already enabled) 2020-06-17T10:09:19Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:19Z DEBUG request body '' 2020-06-17T10:09:19Z DEBUG response status 204 2020-06-17T10:09:19Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=21F73E4EA53FE514F7A4730CF73943AD; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'' 2020-06-17T10:09:19Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:19Z DEBUG request body '' 2020-06-17T10:09:19Z DEBUG response status 200 2020-06-17T10:09:19Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=3445F28DC1735A3DFDF458BC2B2016EC; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:19Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:19Z DEBUG request body 'desc=This certificate profile is for enrolling Security Domain DRM storage certificates\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise RA Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Security Domain DRM storage Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=drmStorageCertSet\npolicyset.drmStorageCertSet.list=1,2,3,4,5,6,7,9\npolicyset.drmStorageCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.drmStorageCertSet.1.constraint.name=Subject Name Constraint\npolicyset.drmStorageCertSet.1.constraint.params.pattern=CN=.*\npolicyset.drmStorageCertSet.1.constraint.params.accept=true\npolicyset.drmStorageCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.drmStorageCertSet.1.default.name=Subject Name Default\npolicyset.drmStorageCertSet.1.default.params.name=\npolicyset.drmStorageCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.drmStorageCertSet.2.constraint.name=Validity Constraint\npolicyset.drmStorageCertSet.2.constraint.params.range=720\npolicyset.drmStorageCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.drmStorageCertSet.2.constraint.params.notAfterCheck=false\npolicyset.drmStorageCertSet.2.default.class_id=validityDefaultImpl\npolicyset.drmStorageCertSet.2.default.name=Validity Default\npolicyset.drmStorageCertSet.2.default.params.range=720\npolicyset.drmStorageCertSet.2.default.params.startTime=0\npolicyset.drmStorageCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.drmStorageCertSet.3.constraint.name=Key Constraint\npolicyset.drmStorageCertSet.3.constraint.params.keyType=-\npolicyset.drmStorageCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.drmStorageCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.drmStorageCertSet.3.default.name=Key Default\npolicyset.drmStorageCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.drmStorageCertSet.4.constraint.name=No Constraint\npolicyset.drmStorageCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.drmStorageCertSet.4.default.name=Authority Key Identifier Default\npolicyset.drmStorageCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.drmStorageCertSet.5.constraint.name=No Constraint\npolicyset.drmStorageCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.drmStorageCertSet.5.default.name=AIA Extension Default\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.drmStorageCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.drmStorageCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.drmStorageCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.drmStorageCertSet.6.default.name=Key Usage Default\npolicyset.drmStorageCertSet.6.default.params.keyUsageCritical=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.drmStorageCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.drmStorageCertSet.7.constraint.name=No Constraint\npolicyset.drmStorageCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.drmStorageCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.drmStorageCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.drmStorageCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.drmStorageCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.drmStorageCertSet.9.constraint.name=No Constraint\npolicyset.drmStorageCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.drmStorageCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.drmStorageCertSet.9.default.name=Signing Alg\npolicyset.drmStorageCertSet.9.default.params.signingAlg=-\nprofileId=caInternalAuthDRMstorageCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:19Z DEBUG response status 409 2020-06-17T10:09:19Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:19Z DEBUG Error migrating 'caInternalAuthDRMstorageCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:19Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caInternalAuthDRMstorageCert?action=enable 2020-06-17T10:09:19Z DEBUG request body '' 2020-06-17T10:09:19Z DEBUG response status 409 2020-06-17T10:09:19Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:18 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:19Z DEBUG Failed to enable profile 'caInternalAuthDRMstorageCert' (it is probably already enabled) 2020-06-17T10:09:19Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:19Z DEBUG request body '' 2020-06-17T10:09:19Z DEBUG response status 204 2020-06-17T10:09:19Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=CA9587AF1A8C41F9F8EFA1DDF7223791; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'' 2020-06-17T10:09:19Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:19Z DEBUG request body '' 2020-06-17T10:09:19Z DEBUG response status 200 2020-06-17T10:09:19Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=E489631B64D107226C21FBE2B92237ED; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:19Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:19Z DEBUG request body 'desc=This certificate profile is for enrolling Security Domain subsystem certificates.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise RA Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Security Domain Subsystem Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\nupdater.list=u1\nupdater.u1.class_id=subsystemGroupUpdaterImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\nprofileId=caInternalAuthSubsystemCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:19Z DEBUG response status 409 2020-06-17T10:09:19Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:19Z DEBUG Error migrating 'caInternalAuthSubsystemCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:19Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caInternalAuthSubsystemCert?action=enable 2020-06-17T10:09:19Z DEBUG request body '' 2020-06-17T10:09:19Z DEBUG response status 409 2020-06-17T10:09:19Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:19Z DEBUG Failed to enable profile 'caInternalAuthSubsystemCert' (it is probably already enabled) 2020-06-17T10:09:19Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:19Z DEBUG request body '' 2020-06-17T10:09:19Z DEBUG response status 204 2020-06-17T10:09:19Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=4D57BD593C78E50D1CF39E9DA17FBB28; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'' 2020-06-17T10:09:19Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:19Z DEBUG request body '' 2020-06-17T10:09:19Z DEBUG response status 200 2020-06-17T10:09:19Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=50FB760AE434C956121071B958637993; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:19Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:19Z DEBUG request body 'desc=This certificate profile is for enrolling Security Domain subsystem certificates with ECC keys.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise RA Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Security Domain Subsystem Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\nupdater.list=u1\nupdater.u1.class_id=subsystemGroupUpdaterImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=-\npolicyset.serverCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\nprofileId=caECInternalAuthSubsystemCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:19Z DEBUG response status 409 2020-06-17T10:09:19Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:19Z DEBUG Error migrating 'caECInternalAuthSubsystemCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:19Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caECInternalAuthSubsystemCert?action=enable 2020-06-17T10:09:19Z DEBUG request body '' 2020-06-17T10:09:19Z DEBUG response status 409 2020-06-17T10:09:19Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:19Z DEBUG Failed to enable profile 'caECInternalAuthSubsystemCert' (it is probably already enabled) 2020-06-17T10:09:19Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:19Z DEBUG request body '' 2020-06-17T10:09:19Z DEBUG response status 204 2020-06-17T10:09:19Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=F1CA2A7BD26AB8F172EBAF5F14A30A04; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'' 2020-06-17T10:09:19Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:19Z DEBUG request body '' 2020-06-17T10:09:19Z DEBUG response status 200 2020-06-17T10:09:19Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=0390D307D33082BD818B37CF42D0DC90; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:19Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:19Z DEBUG request body 'desc=This certificate profile is for enrolling Security Domain OCSP Manager certificates.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise RA Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Security Domain OCSP Manager Signing Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=ocspCertSet\npolicyset.ocspCertSet.list=1,2,3,4,5,6,8,9\npolicyset.ocspCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.ocspCertSet.1.constraint.name=Subject Name Constraint\npolicyset.ocspCertSet.1.constraint.params.pattern=CN=.*\npolicyset.ocspCertSet.1.constraint.params.accept=true\npolicyset.ocspCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.ocspCertSet.1.default.name=Subject Name Default\npolicyset.ocspCertSet.1.default.params.name=\npolicyset.ocspCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.ocspCertSet.2.constraint.name=Validity Constraint\npolicyset.ocspCertSet.2.constraint.params.range=720\npolicyset.ocspCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.ocspCertSet.2.constraint.params.notAfterCheck=false\npolicyset.ocspCertSet.2.default.class_id=validityDefaultImpl\npolicyset.ocspCertSet.2.default.name=Validity Default\npolicyset.ocspCertSet.2.default.params.range=720\npolicyset.ocspCertSet.2.default.params.startTime=0\npolicyset.ocspCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.ocspCertSet.3.constraint.name=Key Constraint\npolicyset.ocspCertSet.3.constraint.params.keyType=-\npolicyset.ocspCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.ocspCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.ocspCertSet.3.default.name=Key Default\npolicyset.ocspCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.ocspCertSet.4.constraint.name=No Constraint\npolicyset.ocspCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.ocspCertSet.4.default.name=Authority Key Identifier Default\npolicyset.ocspCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.ocspCertSet.5.constraint.name=No Constraint\npolicyset.ocspCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.ocspCertSet.5.default.name=AIA Extension Default\npolicyset.ocspCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.ocspCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.ocspCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.ocspCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.ocspCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.ocspCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.ocspCertSet.6.constraint.class_id=extendedKeyUsageExtConstraintImpl\npolicyset.ocspCertSet.6.constraint.name=Extended Key Usage Extension\npolicyset.ocspCertSet.6.constraint.params.exKeyUsageCritical=false\npolicyset.ocspCertSet.6.constraint.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.9\npolicyset.ocspCertSet.6.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.ocspCertSet.6.default.name=Extended Key Usage Default\npolicyset.ocspCertSet.6.default.params.exKeyUsageCritical=false\npolicyset.ocspCertSet.6.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.9\npolicyset.ocspCertSet.8.constraint.class_id=extensionConstraintImpl\npolicyset.ocspCertSet.8.constraint.name=No Constraint\npolicyset.ocspCertSet.8.constraint.params.extCritical=false\npolicyset.ocspCertSet.8.constraint.params.extOID=1.3.6.1.5.5.7.48.1.5\npolicyset.ocspCertSet.8.default.class_id=ocspNoCheckExtDefaultImpl\npolicyset.ocspCertSet.8.default.name=OCSP No Check Extension\npolicyset.ocspCertSet.8.default.params.ocspNoCheckCritical=false\npolicyset.ocspCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.ocspCertSet.9.constraint.name=No Constraint\npolicyset.ocspCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.ocspCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.ocspCertSet.9.default.name=Signing Alg\npolicyset.ocspCertSet.9.default.params.signingAlg=-\nprofileId=caInternalAuthOCSPCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:19Z DEBUG response status 409 2020-06-17T10:09:19Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:19Z DEBUG Error migrating 'caInternalAuthOCSPCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:19Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caInternalAuthOCSPCert?action=enable 2020-06-17T10:09:19Z DEBUG request body '' 2020-06-17T10:09:19Z DEBUG response status 409 2020-06-17T10:09:19Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:19Z DEBUG Failed to enable profile 'caInternalAuthOCSPCert' (it is probably already enabled) 2020-06-17T10:09:19Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:19Z DEBUG request body '' 2020-06-17T10:09:19Z DEBUG response status 204 2020-06-17T10:09:19Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=E65DB26F6CBAEB5F293EA0AA07C4806F; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'' 2020-06-17T10:09:19Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:19Z DEBUG request body '' 2020-06-17T10:09:19Z DEBUG response status 200 2020-06-17T10:09:19Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=1E5FA0BC4FF2FDED657FAB56FAD693CC; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:19Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:19Z DEBUG request body 'desc=This certificate profile is for enrolling audit signing certificates.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise RA Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Audit Signing Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=auditSigningCertSet\npolicyset.auditSigningCertSet.list=1,2,3,4,5,6,9\npolicyset.auditSigningCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.auditSigningCertSet.1.constraint.name=Subject Name Constraint\npolicyset.auditSigningCertSet.1.constraint.params.pattern=CN=.*\npolicyset.auditSigningCertSet.1.constraint.params.accept=true\npolicyset.auditSigningCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.auditSigningCertSet.1.default.name=Subject Name Default\npolicyset.auditSigningCertSet.1.default.params.name=\npolicyset.auditSigningCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.auditSigningCertSet.2.constraint.name=Validity Constraint\npolicyset.auditSigningCertSet.2.constraint.params.range=720\npolicyset.auditSigningCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.auditSigningCertSet.2.constraint.params.notAfterCheck=false\npolicyset.auditSigningCertSet.2.default.class_id=validityDefaultImpl\npolicyset.auditSigningCertSet.2.default.name=Validity Default\npolicyset.auditSigningCertSet.2.default.params.range=720\npolicyset.auditSigningCertSet.2.default.params.startTime=0\npolicyset.auditSigningCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.auditSigningCertSet.3.constraint.name=Key Constraint\npolicyset.auditSigningCertSet.3.constraint.params.keyType=-\npolicyset.auditSigningCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp521\npolicyset.auditSigningCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.auditSigningCertSet.3.default.name=Key Default\npolicyset.auditSigningCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.auditSigningCertSet.4.constraint.name=No Constraint\npolicyset.auditSigningCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.auditSigningCertSet.4.default.name=Authority Key Identifier Default\npolicyset.auditSigningCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.auditSigningCertSet.5.constraint.name=No Constraint\npolicyset.auditSigningCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.auditSigningCertSet.5.default.name=AIA Extension Default\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.auditSigningCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.auditSigningCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.auditSigningCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.auditSigningCertSet.6.default.name=Key Usage Default\npolicyset.auditSigningCertSet.6.default.params.keyUsageCritical=true\npolicyset.auditSigningCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.auditSigningCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.auditSigningCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.auditSigningCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.auditSigningCertSet.9.constraint.name=No Constraint\npolicyset.auditSigningCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.auditSigningCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.auditSigningCertSet.9.default.name=Signing Alg\npolicyset.auditSigningCertSet.9.default.params.signingAlg=-\nprofileId=caInternalAuthAuditSigningCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:19Z DEBUG response status 409 2020-06-17T10:09:19Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:19Z DEBUG Error migrating 'caInternalAuthAuditSigningCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:19Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caInternalAuthAuditSigningCert?action=enable 2020-06-17T10:09:19Z DEBUG request body '' 2020-06-17T10:09:19Z DEBUG response status 409 2020-06-17T10:09:19Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:19Z DEBUG Failed to enable profile 'caInternalAuthAuditSigningCert' (it is probably already enabled) 2020-06-17T10:09:19Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:19Z DEBUG request body '' 2020-06-17T10:09:19Z DEBUG response status 204 2020-06-17T10:09:19Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=ECBE9411BDE6D7DA810EFABABFEA9257; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:19Z DEBUG response body (decoded): b'' 2020-06-17T10:09:19Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:19Z DEBUG request body '' 2020-06-17T10:09:20Z DEBUG response status 200 2020-06-17T10:09:20Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=3404B71101E700AEA8C07FE18923BE27; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:20Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:20Z DEBUG request body "desc=This profile is for enrolling Domain Controller Certificate\nenable=true\nenableBy=admin\nname=Domain Controller\nvisible=true\nauth.instance_id=AgentCertAuth\ninput.list=i1,i2,i3\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\ninput.i3.class_id=genericInputImpl\ninput.i3.params.gi_display_name0=ccm\ninput.i3.params.gi_param_enable0=true\ninput.i3.params.gi_param_name0=ccm\ninput.i3.params.gi_display_name1=GUID\ninput.i3.params.gi_param_enable1=true\ninput.i3.params.gi_param_name1=GUID\ninput.i3.params.gi_num=2\noutput.list=o1,o2\noutput.o1.class_id=certOutputImpl\noutput.o2.class_id=pkcs7OutputImpl\npolicyset.list=set1\npolicyset.set1.list=p2,p4,p5,subj,p6,p8,p9,p12,eku,gen,crldp\npolicyset.set1.subj.constraint.class_id=noConstraintImpl\npolicyset.set1.subj.constraint.name=No Constraint\npolicyset.set1.subj.default.class_id=nsTokenUserKeySubjectNameDefaultImpl\npolicyset.set1.subj.default.name=nsTokenUserKeySubjectNameDefault\n#policyset.set1.p1.default.params.dnpattern=UID=$request.uid$, E=$request.mail$, O=Token Key User\n#policyset.set1.subj.default.params.dnpattern=CN=GEMSTAR,OU=Domain Controllers,DC=test,dc=local\npolicyset.set1.subj.default.params.dnpattern=CN=$request.ccm$\npolicyset.set1.subj.default.params.ldap.enable=false\npolicyset.set1.subj.default.params.ldap.searchName=uid\npolicyset.set1.subj.default.params.ldapStringAttributes=uid,mail\npolicyset.set1.subj.default.params.ldap.basedn=\npolicyset.set1.subj.default.params.ldap.maxConns=4\npolicyset.set1.subj.default.params.ldap.minConns=1\npolicyset.set1.subj.default.params.ldap.ldapconn.Version=2\npolicyset.set1.subj.default.params.ldap.ldapconn.host=\npolicyset.set1.subj.default.params.ldap.ldapconn.port=\npolicyset.set1.subj.default.params.ldap.ldapconn.secureConn=false\npolicyset.set1.p2.constraint.class_id=noConstraintImpl\npolicyset.set1.p2.constraint.name=No Constraint\npolicyset.set1.p2.default.class_id=validityDefaultImpl\npolicyset.set1.p2.default.name=Validity Default\npolicyset.set1.p2.default.params.range=1825\npolicyset.set1.p2.default.params.startTime=0\npolicyset.set1.p4.constraint.class_id=noConstraintImpl\npolicyset.set1.p4.constraint.name=No Constraint\npolicyset.set1.p4.default.class_id=signingAlgDefaultImpl\npolicyset.set1.p4.default.name=Signing Algorithm Default\npolicyset.set1.p4.default.params.signingAlg=-\npolicyset.set1.p5.constraint.class_id=noConstraintImpl\npolicyset.set1.p5.constraint.name=No Constraint\npolicyset.set1.p5.default.class_id=keyUsageExtDefaultImpl\npolicyset.set1.p5.default.name=Key Usage Extension Default\npolicyset.set1.p5.default.params.keyUsageCritical=true\npolicyset.set1.p5.default.params.keyUsageCrlSign=false\npolicyset.set1.p5.default.params.keyUsageDataEncipherment=false\npolicyset.set1.p5.default.params.keyUsageDecipherOnly=false\npolicyset.set1.p5.default.params.keyUsageDigitalSignature=true\npolicyset.set1.p5.default.params.keyUsageEncipherOnly=false\npolicyset.set1.p5.default.params.keyUsageKeyAgreement=false\npolicyset.set1.p5.default.params.keyUsageKeyCertSign=false\npolicyset.set1.p5.default.params.keyUsageKeyEncipherment=true\npolicyset.set1.p5.default.params.keyUsageNonRepudiation=false\npolicyset.set1.p6.constraint.class_id=noConstraintImpl\npolicyset.set1.p6.constraint.name=No Constraint\npolicyset.set1.p6.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.set1.p6.default.name=Subject Alternative Name Extension Default\npolicyset.set1.p6.default.params.subjAltExtGNEnable_0=true\npolicyset.set1.p6.default.params.subjAltExtGNEnable_1=true\npolicyset.set1.p6.default.params.subjAltExtPattern_0=$request.ccm$\npolicyset.set1.p6.default.params.subjAltExtType_0=DNSName\npolicyset.set1.p6.default.params.subjAltExtPattern_1=(Any)1.3.6.1.4.1.311.25.1,0410$request.GUID$\npolicyset.set1.p6.default.params.subjAltExtType_1=OtherName\npolicyset.set1.p6.default.params.subjAltNameExtCritical=false\npolicyset.set1.p6.default.params.subjAltNameNumGNs=2\npolicyset.set1.5.constraint.class_id=noConstraintImpl\npolicyset.set1.5.constraint.name=No Constraint\npolicyset.set1.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.set1.5.default.name=AIA Extension Default\npolicyset.set1.5.default.params.authInfoAccessADEnable_0=true\npolicyset.set1.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.set1.5.default.params.authInfoAccessADLocation_0=http://localhost.localdomain:9180/ca/ee/ca/getCRL?crlIssuingPoint=MasterCRL&op=getCRL&crlDisplayType=cachedCRL&submit=Submit\npolicyset.set1.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.2\npolicyset.set1.5.default.params.authInfoAccessCritical=false\npolicyset.set1.5.default.params.authInfoAccessNumADs=1\npolicyset.set1.eku.constraint.class_id=noConstraintImpl\npolicyset.set1.eku.constraint.name=No Constraint\npolicyset.set1.eku.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.set1.eku.default.name=Extended Key Usage Extension Default\npolicyset.set1.eku.default.params.exKeyUsageCritical=false\npolicyset.set1.eku.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.set1.p8.constraint.class_id=noConstraintImpl\npolicyset.set1.p8.constraint.name=No Constraint\npolicyset.set1.p8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.set1.p8.default.name=Subject Key Identifier Default\npolicyset.set1.p9.constraint.class_id=noConstraintImpl\npolicyset.set1.p9.constraint.name=No Constraint\npolicyset.set1.p9.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.set1.p9.default.name=Authority Key Identifier Extension Default\npolicyset.set1.p12.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.set1.p12.constraint.name=Basic Constraints Extension Constraint\npolicyset.set1.p12.constraint.params.basicConstraintsCritical=-\npolicyset.set1.p12.constraint.params.basicConstraintsIsCA=-\npolicyset.set1.p12.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.set1.p12.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.set1.p12.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.set1.p12.default.name=Basic Constraints Extension Default\npolicyset.set1.p12.default.params.basicConstraintsCritical=false\npolicyset.set1.p12.default.params.basicConstraintsIsCA=false\npolicyset.set1.p12.default.params.basicConstraintsPathLen=-1\npolicyset.set1.crldp.constraint.class_id=noConstraintImpl\npolicyset.set1.crldp.constraint.name=No Constraint\npolicyset.set1.crldp.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.set1.crldp.default.name=crlDistributionPointsExtDefaultImpl\npolicyset.set1.crldp.default.params.crlDistPointsCritical=false\npolicyset.set1.crldp.default.params.crlDistPointsNum=1\npolicyset.set1.crldp.default.params.crlDistPointsEnable_0=true\npolicyset.set1.crldp.default.params.crlDistPointsIssuerName_0=\npolicyset.set1.crldp.default.params.crlDistPointsIssuerType_0=\npolicyset.set1.crldp.default.params.crlDistPointsPointName_0=http://localhost.localdomain:9180/ca/ee/ca/getCRL?crlIssuingPoint=MasterCRL&op=getCRL&crlDisplayType=cachedCRL&submit=Submit\npolicyset.set1.crldp.default.params.crlDistPointsPointType_0=URIName\npolicyset.set1.crldp.default.params.crlDistPointsReasons_0=\npolicyset.set1.gen.constraint.class_id=noConstraintImpl\npolicyset.set1.gen.constraint.name=No Constraint\npolicyset.set1.gen.default.class_id=genericExtDefaultImpl\npolicyset.set1.gen.default.name=Generic Extension\n#This is the Microsoft 'Certificate Template Name' Extensions. The Value is 'DomainController'\npolicyset.set1.gen.default.params.genericExtOID=1.3.6.1.4.1.311.20.2\npolicyset.set1.gen.default.params.genericExtData=1e200044006f006d00610069006e0043006f006e00740072006f006c006c00650072\nprofileId=DomainController\nclassId=caEnrollImpl\n" 2020-06-17T10:09:20Z DEBUG response status 409 2020-06-17T10:09:20Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:20Z DEBUG Error migrating 'DomainController': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:20Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/DomainController?action=enable 2020-06-17T10:09:20Z DEBUG request body '' 2020-06-17T10:09:20Z DEBUG response status 409 2020-06-17T10:09:20Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:20Z DEBUG Failed to enable profile 'DomainController' (it is probably already enabled) 2020-06-17T10:09:20Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:20Z DEBUG request body '' 2020-06-17T10:09:20Z DEBUG response status 204 2020-06-17T10:09:20Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=774BD68FC339C33C79D0B83C186A472A; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'' 2020-06-17T10:09:20Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:20Z DEBUG request body '' 2020-06-17T10:09:20Z DEBUG response status 200 2020-06-17T10:09:20Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=6A34ACF539F35C6E90CB478F86911AE0; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:20Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:20Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates with RA agent authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=RA Agent-Authenticated User Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=userCertSet\npolicyset.userCertSet.list=1,2,3,4,5,6,7,8,9\npolicyset.userCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.userCertSet.1.constraint.name=Subject Name Constraint\npolicyset.userCertSet.1.constraint.params.pattern=.*UID=.*\npolicyset.userCertSet.1.constraint.params.accept=true\npolicyset.userCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.userCertSet.1.default.name=Subject Name Default\npolicyset.userCertSet.1.default.params.name=\npolicyset.userCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.userCertSet.2.constraint.name=Validity Constraint\npolicyset.userCertSet.2.constraint.params.range=365\npolicyset.userCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.userCertSet.2.constraint.params.notAfterCheck=false\npolicyset.userCertSet.2.default.class_id=validityDefaultImpl\npolicyset.userCertSet.2.default.name=Validity Default\npolicyset.userCertSet.2.default.params.range=180\npolicyset.userCertSet.2.default.params.startTime=0\npolicyset.userCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.userCertSet.3.constraint.name=Key Constraint\npolicyset.userCertSet.3.constraint.params.keyType=RSA\npolicyset.userCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.userCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.userCertSet.3.default.name=Key Default\npolicyset.userCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.4.constraint.name=No Constraint\npolicyset.userCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.userCertSet.4.default.name=Authority Key Identifier Default\npolicyset.userCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.5.constraint.name=No Constraint\npolicyset.userCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.userCertSet.5.default.name=AIA Extension Default\npolicyset.userCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.userCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.userCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.userCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.userCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.userCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.userCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.userCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.userCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.userCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.userCertSet.6.default.name=Key Usage Default\npolicyset.userCertSet.6.default.params.keyUsageCritical=true\npolicyset.userCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.7.constraint.name=No Constraint\npolicyset.userCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.userCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.userCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.userCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.userCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.8.constraint.name=No Constraint\npolicyset.userCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.userCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.userCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.userCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.userCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.userCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.userCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.userCertSet.9.constraint.name=No Constraint\npolicyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.userCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.userCertSet.9.default.name=Signing Alg\npolicyset.userCertSet.9.default.params.signingAlg=-\nprofileId=caDualRAuserCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:20Z DEBUG response status 409 2020-06-17T10:09:20Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:20Z DEBUG Error migrating 'caDualRAuserCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:20Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caDualRAuserCert?action=enable 2020-06-17T10:09:20Z DEBUG request body '' 2020-06-17T10:09:20Z DEBUG response status 409 2020-06-17T10:09:20Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:20Z DEBUG Failed to enable profile 'caDualRAuserCert' (it is probably already enabled) 2020-06-17T10:09:20Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:20Z DEBUG request body '' 2020-06-17T10:09:20Z DEBUG response status 204 2020-06-17T10:09:20Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=481383B474CF8895DC021C916AA8A534; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'' 2020-06-17T10:09:20Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:20Z DEBUG request body '' 2020-06-17T10:09:20Z DEBUG response status 200 2020-06-17T10:09:20Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=F01D40A3D97959E179371D0B630FDA8B; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:20Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:20Z DEBUG request body 'desc=This certificate profile is for enrolling RA agent user certificates with RA agent authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=RA Agent-Authenticated Agent User Certificate Enrollment\ninput.list=i1,i2,i3\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\ninput.i3.class_id=subjectDNInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=userCertSet\npolicyset.userCertSet.list=1,2,3,4,5,6,7,8,9\npolicyset.userCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.userCertSet.1.constraint.name=Subject Name Constraint\npolicyset.userCertSet.1.constraint.params.pattern=UID=.*\npolicyset.userCertSet.1.constraint.params.accept=true\npolicyset.userCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.userCertSet.1.default.name=Subject Name Default\npolicyset.userCertSet.1.default.params.name=\npolicyset.userCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.userCertSet.2.constraint.name=Validity Constraint\npolicyset.userCertSet.2.constraint.params.range=365\npolicyset.userCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.userCertSet.2.constraint.params.notAfterCheck=false\npolicyset.userCertSet.2.default.class_id=validityDefaultImpl\npolicyset.userCertSet.2.default.name=Validity Default\npolicyset.userCertSet.2.default.params.range=180\npolicyset.userCertSet.2.default.params.startTime=0\npolicyset.userCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.userCertSet.3.constraint.name=Key Constraint\npolicyset.userCertSet.3.constraint.params.keyType=RSA\npolicyset.userCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.userCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.userCertSet.3.default.name=Key Default\npolicyset.userCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.4.constraint.name=No Constraint\npolicyset.userCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.userCertSet.4.default.name=Authority Key Identifier Default\npolicyset.userCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.5.constraint.name=No Constraint\npolicyset.userCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.userCertSet.5.default.name=AIA Extension Default\npolicyset.userCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.userCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.userCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.userCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.userCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.userCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.userCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.userCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.userCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.userCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.userCertSet.6.default.name=Key Usage Default\npolicyset.userCertSet.6.default.params.keyUsageCritical=true\npolicyset.userCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.7.constraint.name=No Constraint\npolicyset.userCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.userCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.userCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.userCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.userCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.8.constraint.name=No Constraint\npolicyset.userCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.userCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.userCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.userCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.userCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.userCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.userCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.userCertSet.9.constraint.name=No Constraint\npolicyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.userCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.userCertSet.9.default.name=Signing Alg\npolicyset.userCertSet.9.default.params.signingAlg=-\nprofileId=caRAagentCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:20Z DEBUG response status 409 2020-06-17T10:09:20Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:19 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:20Z DEBUG Error migrating 'caRAagentCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:20Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caRAagentCert?action=enable 2020-06-17T10:09:20Z DEBUG request body '' 2020-06-17T10:09:20Z DEBUG response status 409 2020-06-17T10:09:20Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:20Z DEBUG Failed to enable profile 'caRAagentCert' (it is probably already enabled) 2020-06-17T10:09:20Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:20Z DEBUG request body '' 2020-06-17T10:09:20Z DEBUG response status 204 2020-06-17T10:09:20Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=3BD49CF8191E20335870BF69D8AD1C65; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'' 2020-06-17T10:09:20Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:20Z DEBUG request body '' 2020-06-17T10:09:20Z DEBUG response status 200 2020-06-17T10:09:20Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=BFEC084AF1D2218F1FADE4EC40BB0A9B; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:20Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:20Z DEBUG request body 'desc=This certificate profile is for enrolling server certificates with RA agent authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=RA Agent-Authenticated Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=365\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=180\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.9.default.name=copy CN to SAN Default\nprofileId=caRAserverCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:20Z DEBUG response status 409 2020-06-17T10:09:20Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:20Z DEBUG Error migrating 'caRAserverCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:20Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caRAserverCert?action=enable 2020-06-17T10:09:20Z DEBUG request body '' 2020-06-17T10:09:20Z DEBUG response status 409 2020-06-17T10:09:20Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:20Z DEBUG Failed to enable profile 'caRAserverCert' (it is probably already enabled) 2020-06-17T10:09:20Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:20Z DEBUG request body '' 2020-06-17T10:09:20Z DEBUG response status 204 2020-06-17T10:09:20Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=6A9A7CAEB2EB9E5C8CAB62F32D7B50E4; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'' 2020-06-17T10:09:20Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:20Z DEBUG request body '' 2020-06-17T10:09:20Z DEBUG response status 200 2020-06-17T10:09:20Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=6AE57655D5AB03130FA4B1ED005C909D; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:20Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:20Z DEBUG request body 'desc=This certificate profile is for enrolling device certificates to contain UUID in the Subject Alternative Name extension\nvisible=true\nenable=false\nenableBy=admin\nname=Manual device Dual-Use Certificate Enrollment to contain UUID in SAN\nauth.class_id=\ninput.list=i1,i2,i3\ninput.i1.class_id=keyGenInputImpl\ninput.i2.class_id=subjectNameInputImpl\ninput.i3.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=userCertSet\npolicyset.userCertSet.list=1,2,3,4,5,6,7,8,9\npolicyset.userCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.userCertSet.1.constraint.name=Subject Name Constraint\npolicyset.userCertSet.1.constraint.params.pattern=UID=.*\npolicyset.userCertSet.1.constraint.params.accept=true\npolicyset.userCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.userCertSet.1.default.name=Subject Name Default\npolicyset.userCertSet.1.default.params.name=\npolicyset.userCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.userCertSet.2.constraint.name=Validity Constraint\npolicyset.userCertSet.2.constraint.params.range=365\npolicyset.userCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.userCertSet.2.constraint.params.notAfterCheck=false\npolicyset.userCertSet.2.default.class_id=validityDefaultImpl\npolicyset.userCertSet.2.default.name=Validity Default\npolicyset.userCertSet.2.default.params.range=180\npolicyset.userCertSet.2.default.params.startTime=0\npolicyset.userCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.userCertSet.3.constraint.name=Key Constraint\npolicyset.userCertSet.3.constraint.params.keyType=-\npolicyset.userCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.userCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.userCertSet.3.default.name=Key Default\npolicyset.userCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.4.constraint.name=No Constraint\npolicyset.userCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.userCertSet.4.default.name=Authority Key Identifier Default\npolicyset.userCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.5.constraint.name=No Constraint\npolicyset.userCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.userCertSet.5.default.name=AIA Extension Default\npolicyset.userCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.userCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.userCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.userCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.userCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.userCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.userCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.userCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.userCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.userCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.userCertSet.6.default.name=Key Usage Default\npolicyset.userCertSet.6.default.params.keyUsageCritical=true\npolicyset.userCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.7.constraint.name=No Constraint\npolicyset.userCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.userCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.userCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.userCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.userCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.8.constraint.name=No Constraint\npolicyset.userCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.userCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.userCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.userCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.userCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.userCertSet.8.default.params.subjAltExtType_1=OtherName\npolicyset.userCertSet.8.default.params.subjAltExtPattern_1=(IA5String)1.2.3.4,$server.source$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_1=true\npolicyset.userCertSet.8.default.params.subjAltExtSource_1=UUID4\npolicyset.userCertSet.8.default.params.subjAltNameNumGNs=2\npolicyset.userCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.userCertSet.9.constraint.name=No Constraint\npolicyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.userCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.userCertSet.9.default.name=Signing Alg\npolicyset.userCertSet.9.default.params.signingAlg=-\nprofileId=caUUIDdeviceCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:20Z DEBUG response status 409 2020-06-17T10:09:20Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:20Z DEBUG Error migrating 'caUUIDdeviceCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:20Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caUUIDdeviceCert?action=enable 2020-06-17T10:09:20Z DEBUG request body '' 2020-06-17T10:09:20Z DEBUG response status 204 2020-06-17T10:09:20Z DEBUG response headers Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'' 2020-06-17T10:09:20Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:20Z DEBUG request body '' 2020-06-17T10:09:20Z DEBUG response status 204 2020-06-17T10:09:20Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=4B1B7728FA71D4815CC4B67C21063248; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'' 2020-06-17T10:09:20Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:20Z DEBUG request body '' 2020-06-17T10:09:20Z DEBUG response status 200 2020-06-17T10:09:20Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=0214A0355CA75835F3E2B6A9450BB599; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:20Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:20Z DEBUG request body 'desc=This certificate profile is for renewing SSL client certificates.\nvisible=true\nenable=true\nenableBy=admin\nrenewal=true\nauth.instance_id=SSLclientCertAuth\nname=Renewal: Self-renew user SSL client certificates\noutput.list=o1\noutput.o1.class_id=certOutputImpl\nprofileId=caSSLClientSelfRenewal\nclassId=caEnrollImpl\n' 2020-06-17T10:09:20Z DEBUG response status 409 2020-06-17T10:09:20Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:20Z DEBUG Error migrating 'caSSLClientSelfRenewal': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:20Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caSSLClientSelfRenewal?action=enable 2020-06-17T10:09:20Z DEBUG request body '' 2020-06-17T10:09:20Z DEBUG response status 409 2020-06-17T10:09:20Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:20Z DEBUG Failed to enable profile 'caSSLClientSelfRenewal' (it is probably already enabled) 2020-06-17T10:09:20Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:20Z DEBUG request body '' 2020-06-17T10:09:20Z DEBUG response status 204 2020-06-17T10:09:20Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=834EBDE4735495A36C1DA02DBD971357; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'' 2020-06-17T10:09:20Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:20Z DEBUG request body '' 2020-06-17T10:09:20Z DEBUG response status 200 2020-06-17T10:09:20Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=58E329B4D184186C943CC9AD327D32F3; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:20Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:20Z DEBUG request body 'desc=This certificate profile is for renewing a certificate by serial number by using directory based authentication.\nvisible=true\nenable=true\nenableBy=admin\nrenewal=true\nauth.instance_id=UserDirEnrollment\nauthz.acl=user_origreq="auth_token.uid"\nname=Renewal: Directory-Authenticated User Certificate Self-Renew profile\ninput.list=i1\ninput.i1.class_id=serialNumRenewInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\nprofileId=caDirUserRenewal\nclassId=caEnrollImpl\n' 2020-06-17T10:09:20Z DEBUG response status 409 2020-06-17T10:09:20Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:20Z DEBUG Error migrating 'caDirUserRenewal': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:20Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caDirUserRenewal?action=enable 2020-06-17T10:09:20Z DEBUG request body '' 2020-06-17T10:09:20Z DEBUG response status 409 2020-06-17T10:09:20Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:20Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:20Z DEBUG Failed to enable profile 'caDirUserRenewal' (it is probably already enabled) 2020-06-17T10:09:20Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:20Z DEBUG request body '' 2020-06-17T10:09:21Z DEBUG response status 204 2020-06-17T10:09:21Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=0B052DB316584E4D38B5C88497A91EDE; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'' 2020-06-17T10:09:21Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:21Z DEBUG request body '' 2020-06-17T10:09:21Z DEBUG response status 200 2020-06-17T10:09:21Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=DE14D2E8E9CF3C62FF3C7CB0973D309E; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:21Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:21Z DEBUG request body 'desc=This certificate profile is for renewing certificates to be approved manually by agents.\nvisible=true\nenable=true\nenableBy=admin\nrenewal=true\nauth.instance_id=\nname=Renewal: Renew certificate to be manually approved by agents\ninput.list=i1\ninput.i1.class_id=serialNumRenewInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\nprofileId=caManualRenewal\nclassId=caEnrollImpl\n' 2020-06-17T10:09:21Z DEBUG response status 409 2020-06-17T10:09:21Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:21Z DEBUG Error migrating 'caManualRenewal': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:21Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caManualRenewal?action=enable 2020-06-17T10:09:21Z DEBUG request body '' 2020-06-17T10:09:21Z DEBUG response status 409 2020-06-17T10:09:21Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:21Z DEBUG Failed to enable profile 'caManualRenewal' (it is probably already enabled) 2020-06-17T10:09:21Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:21Z DEBUG request body '' 2020-06-17T10:09:21Z DEBUG response status 204 2020-06-17T10:09:21Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=CA6B415701FD0977CB436EA7FADD289C; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'' 2020-06-17T10:09:21Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:21Z DEBUG request body '' 2020-06-17T10:09:21Z DEBUG response status 200 2020-06-17T10:09:21Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=B0EC547796996D18F6593D7EE92860A8; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:21Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:21Z DEBUG request body 'desc=This profile is for enrolling MS Login Certificate\nenable=true\nenableBy=admin\nname=Token User MS Login Certificate Enrollment\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1\ninput.i1.class_id=nsNKeyCertReqInputImpl\ninput.i1.name=nsNKeyCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=nsNKeyOutputImpl\noutput.o2.name=nsNKeyOutputImpl\npolicyset.list=set1\n#policyset.set1.list=p2,p4,p5,p1,p6,p7,p8,p9,p12,p13,p14\npolicyset.set1.list=p2,p4,p5,p1,p6,p8,p9,p12,p13,p14,p15\npolicyset.set1.p1.constraint.class_id=noConstraintImpl\npolicyset.set1.p1.constraint.name=No Constraint\npolicyset.set1.p1.default.class_id=nsTokenUserKeySubjectNameDefaultImpl\npolicyset.set1.p1.default.name=nsTokenUserKeySubjectNameDefault\npolicyset.set1.p1.default.params.dnpattern=CN=uid=$request.uid$,E=$request.mail$, ou=$request.upn$, o=example\n#changed ldap.enable to true to support SMIME\npolicyset.set1.p1.default.params.ldap.enable=true\npolicyset.set1.p1.default.params.ldap.searchName=uid\npolicyset.set1.p1.default.params.ldapStringAttributes=uid,mail,givenName,sn,upn\npolicyset.set1.p1.default.params.ldap.basedn=ou=People,dc=example,dc=com\npolicyset.set1.p1.default.params.ldap.maxConns=4\npolicyset.set1.p1.default.params.ldap.minConns=1\npolicyset.set1.p1.default.params.ldap.ldapconn.Version=2\npolicyset.set1.p1.default.params.ldap.ldapconn.host=localhost.localdomain\npolicyset.set1.p1.default.params.ldap.ldapconn.port=389\npolicyset.set1.p1.default.params.ldap.ldapconn.secureConn=false\npolicyset.set1.p2.constraint.class_id=noConstraintImpl\npolicyset.set1.p2.constraint.name=No Constraint\npolicyset.set1.p2.default.class_id=validityDefaultImpl\npolicyset.set1.p2.default.name=Validity Default\npolicyset.set1.p2.default.params.range=1825\npolicyset.set1.p2.default.params.startTime=0\npolicyset.set1.p4.constraint.class_id=noConstraintImpl\npolicyset.set1.p4.constraint.name=No Constraint\npolicyset.set1.p4.default.class_id=signingAlgDefaultImpl\npolicyset.set1.p4.default.name=Signing Algorithm Default\npolicyset.set1.p4.default.params.signingAlg=-\npolicyset.set1.p5.constraint.class_id=noConstraintImpl\npolicyset.set1.p5.constraint.name=No Constraint\npolicyset.set1.p5.default.class_id=keyUsageExtDefaultImpl\npolicyset.set1.p5.default.name=Key Usage Extension Default\npolicyset.set1.p5.default.params.keyUsageCritical=true\npolicyset.set1.p5.default.params.keyUsageCrlSign=false\npolicyset.set1.p5.default.params.keyUsageDataEncipherment=false\npolicyset.set1.p5.default.params.keyUsageDecipherOnly=false\npolicyset.set1.p5.default.params.keyUsageDigitalSignature=true\npolicyset.set1.p5.default.params.keyUsageEncipherOnly=false\npolicyset.set1.p5.default.params.keyUsageKeyAgreement=false\npolicyset.set1.p5.default.params.keyUsageKeyCertSign=false\npolicyset.set1.p5.default.params.keyUsageKeyEncipherment=false\npolicyset.set1.p5.default.params.keyUsageNonRepudiation=true\npolicyset.set1.p6.constraint.class_id=noConstraintImpl\npolicyset.set1.p6.constraint.name=No Constraint\npolicyset.set1.p6.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.set1.p6.default.name=Subject Alternative Name Extension Default\npolicyset.set1.p6.default.params.subjAltExtGNEnable_0=true\npolicyset.set1.p6.default.params.subjAltExtGNEnable_1=true\npolicyset.set1.p6.default.params.subjAltExtGNEnable_2=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_3=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_4=false\npolicyset.set1.p6.default.params.subjAltExtPattern_0=$request.mail$\npolicyset.set1.p6.default.params.subjAltExtPattern_1=(UTF8String)1.3.6.1.4.1.311.20.2.3,$request.upn$\npolicyset.set1.p6.default.params.subjAltExtPattern_2=\npolicyset.set1.p6.default.params.subjAltExtPattern_3=\npolicyset.set1.p6.default.params.subjAltExtPattern_4=\npolicyset.set1.p6.default.params.subjAltExtType_0=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_1=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_2=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_3=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_4=RFC822Name\npolicyset.set1.p6.default.params.subjAltNameExtCritical=false\npolicyset.set1.p6.default.params.subjAltNameNumGNs=2\npolicyset.set1.p7.constraint.class_id=noConstraintImpl\npolicyset.set1.p7.constraint.name=No Constraint\npolicyset.set1.p7.default.class_id=certificatePoliciesExtDefaultImpl\npolicyset.set1.p7.default.name=Certificate Policies Extension Default\npolicyset.set1.p7.default.params.Critical=false\npolicyset.set1.p7.default.params.PoliciesExt.num=5\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.enable=true\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.explicitText.value=\n policyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\n policyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.enable=false\n policyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.explicitText.value=\n policyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\n policyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\n policyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p8.constraint.class_id=noConstraintImpl\npolicyset.set1.p8.constraint.name=No Constraint\npolicyset.set1.p8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.set1.p8.default.name=Subject Key Identifier Default\npolicyset.set1.p9.constraint.class_id=noConstraintImpl\npolicyset.set1.p9.constraint.name=No Constraint\npolicyset.set1.p9.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.set1.p9.default.name=Authority Key Identifier Extension Default\npolicyset.set1.p12.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.set1.p12.constraint.name=Basic Constraints Extension Constraint\npolicyset.set1.p12.constraint.params.basicConstraintsCritical=-\npolicyset.set1.p12.constraint.params.basicConstraintsIsCA=-\npolicyset.set1.p12.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.set1.p12.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.set1.p12.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.set1.p12.default.name=Basic Constraints Extension Default\npolicyset.set1.p12.default.params.basicConstraintsCritical=false\npolicyset.set1.p12.default.params.basicConstraintsIsCA=false\npolicyset.set1.p12.default.params.basicConstraintsPathLen=-1\npolicyset.set1.p13.constraint.class_id=noConstraintImpl\npolicyset.set1.p13.constraint.name=No Constraint\npolicyset.set1.p13.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.name=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.params.crlDistPointsCritical=false\npolicyset.set1.p13.default.params.crlDistPointsNum=1\npolicyset.set1.p13.default.params.crlDistPointsEnable_0=true\npolicyset.set1.p13.default.params.crlDistPointsIssuerName_0=\npolicyset.set1.p13.default.params.crlDistPointsIssuerType_0=\npolicyset.set1.p13.default.params.crlDistPointsPointName_0=http://localhost.localdomain:9443/ca/ee/ca/getCRL?crlIssuingPoint=MasterCRL&op=getCRL\npolicyset.set1.p13.default.params.crlDistPointsPointType_0=URIName\npolicyset.set1.p13.default.params.crlDistPointsReasons_0=\npolicyset.set1.p14.constraint.class_id=noConstraintImpl\npolicyset.set1.p14.constraint.name=No Constraint\npolicyset.set1.p14.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.set1.p14.default.name=AIA Extension Default\npolicyset.set1.p14.default.params.authInfoAccessADEnable_0=true\npolicyset.set1.p14.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.set1.p14.default.params.authInfoAccessADLocation_0=http://localhost.localdomain:9443/ca/ocsp\npolicyset.set1.p14.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.set1.p14.default.params.authInfoAccessCritical=false\npolicyset.set1.p14.default.params.authInfoAccessNumADs=1\npolicyset.set1.p15.constraint.class_id=noConstraintImpl\npolicyset.set1.p15.constraint.name=No Constraint\npolicyset.set1.p15.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.set1.p15.default.name=Extended Key Usage Extension Default\npolicyset.set1.p15.default.params.exKeyUsageCritical=false\npolicyset.set1.p15.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.4.1.311.20.2.2\n\nprofileId=caTokenMSLoginEnrollment\nclassId=caUserCertEnrollImpl\n' 2020-06-17T10:09:21Z DEBUG response status 409 2020-06-17T10:09:21Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:21Z DEBUG Error migrating 'caTokenMSLoginEnrollment': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:21Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caTokenMSLoginEnrollment?action=enable 2020-06-17T10:09:21Z DEBUG request body '' 2020-06-17T10:09:21Z DEBUG response status 409 2020-06-17T10:09:21Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:21Z DEBUG Failed to enable profile 'caTokenMSLoginEnrollment' (it is probably already enabled) 2020-06-17T10:09:21Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:21Z DEBUG request body '' 2020-06-17T10:09:21Z DEBUG response status 204 2020-06-17T10:09:21Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=DA0A29E9579C49C2DC545704CEE8B585; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'' 2020-06-17T10:09:21Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:21Z DEBUG request body '' 2020-06-17T10:09:21Z DEBUG response status 200 2020-06-17T10:09:21Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=5D22278991614A7166EAD85D4BE5D645; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:21Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:21Z DEBUG request body 'desc=This certificate profile is for renewing a token certificate\nvisible=false\nenable=true\nenableBy=admin\nrenewal=true\nauth.instance_id=AgentCertAuth\nname=smart card token signing cert renewal profile\ninput.list=i1\ninput.i1.class_id=serialNumRenewInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\nprofileId=caTokenUserSigningKeyRenewal\nclassId=caUserCertEnrollImpl\n' 2020-06-17T10:09:21Z DEBUG response status 409 2020-06-17T10:09:21Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:20 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:21Z DEBUG Error migrating 'caTokenUserSigningKeyRenewal': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:21Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caTokenUserSigningKeyRenewal?action=enable 2020-06-17T10:09:21Z DEBUG request body '' 2020-06-17T10:09:21Z DEBUG response status 409 2020-06-17T10:09:21Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:21Z DEBUG Failed to enable profile 'caTokenUserSigningKeyRenewal' (it is probably already enabled) 2020-06-17T10:09:21Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:21Z DEBUG request body '' 2020-06-17T10:09:21Z DEBUG response status 204 2020-06-17T10:09:21Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=1D07347DAF984A0D84D98F12A6D8EDA6; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'' 2020-06-17T10:09:21Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:21Z DEBUG request body '' 2020-06-17T10:09:21Z DEBUG response status 200 2020-06-17T10:09:21Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=897DA7B483AA1CCA92F27CA74982BA66; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:21Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:21Z DEBUG request body 'desc=This certificate profile is for renewing a token encryption certificate\nvisible=false\nenable=true\nenableBy=admin\nrenewal=true\nauth.instance_id=AgentCertAuth\nname=smart card token encryption cert renewal profile\ninput.list=i1\ninput.i1.class_id=serialNumRenewInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\nprofileId=caTokenUserEncryptionKeyRenewal\nclassId=caUserCertEnrollImpl\n' 2020-06-17T10:09:21Z DEBUG response status 409 2020-06-17T10:09:21Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:21Z DEBUG Error migrating 'caTokenUserEncryptionKeyRenewal': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:21Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caTokenUserEncryptionKeyRenewal?action=enable 2020-06-17T10:09:21Z DEBUG request body '' 2020-06-17T10:09:21Z DEBUG response status 409 2020-06-17T10:09:21Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:21Z DEBUG Failed to enable profile 'caTokenUserEncryptionKeyRenewal' (it is probably already enabled) 2020-06-17T10:09:21Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:21Z DEBUG request body '' 2020-06-17T10:09:21Z DEBUG response status 204 2020-06-17T10:09:21Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=61EF925AC36C99AC716CD262EB9A92DE; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'' 2020-06-17T10:09:21Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:21Z DEBUG request body '' 2020-06-17T10:09:21Z DEBUG response status 200 2020-06-17T10:09:21Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=2566461B37238231A01A8FCA5C164627; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:21Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:21Z DEBUG request body 'desc=This certificate profile is for renewing a token authentication certificate\nvisible=false\nenable=true\nenableBy=admin\nrenewal=true\nauth.instance_id=AgentCertAuth\nname=smart card token authentication cert renewal profile\ninput.list=i1\ninput.i1.class_id=serialNumRenewInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\nprofileId=caTokenUserAuthKeyRenewal\nclassId=caUserCertEnrollImpl\n' 2020-06-17T10:09:21Z DEBUG response status 409 2020-06-17T10:09:21Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:21Z DEBUG Error migrating 'caTokenUserAuthKeyRenewal': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:21Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caTokenUserAuthKeyRenewal?action=enable 2020-06-17T10:09:21Z DEBUG request body '' 2020-06-17T10:09:21Z DEBUG response status 409 2020-06-17T10:09:21Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:21Z DEBUG Failed to enable profile 'caTokenUserAuthKeyRenewal' (it is probably already enabled) 2020-06-17T10:09:21Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:21Z DEBUG request body '' 2020-06-17T10:09:21Z DEBUG response status 204 2020-06-17T10:09:21Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=61C0FDE04B2E116EFF8B7515A0D9BA85; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'' 2020-06-17T10:09:21Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:21Z DEBUG request body '' 2020-06-17T10:09:21Z DEBUG response status 200 2020-06-17T10:09:21Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=8D66CA7AF08BC781D8F2EF6EC04D0E90; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:21Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:21Z DEBUG request body 'desc=This is an IPA profile for enrolling Jar Signing certificates.\nenable=true\nenableBy=admin\nname=Manual Jar Signing Certificate Enrollment\nvisible=false\nauth.class_id=\nauth.instance_id=raCertAuth\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=caJarSigningSet\npolicyset.caJarSigningSet.list=1,2,3,4,5,6\npolicyset.caJarSigningSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.caJarSigningSet.1.constraint.name=Subject Name Constraint\npolicyset.caJarSigningSet.1.constraint.params.accept=true\npolicyset.caJarSigningSet.1.constraint.params.pattern=.*\npolicyset.caJarSigningSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.caJarSigningSet.1.default.name=Subject Name Default\npolicyset.caJarSigningSet.1.default.params.name=\npolicyset.caJarSigningSet.2.constraint.class_id=validityConstraintImpl\npolicyset.caJarSigningSet.2.constraint.name=Validity Constraint\npolicyset.caJarSigningSet.2.constraint.params.notAfterCheck=false\npolicyset.caJarSigningSet.2.constraint.params.notBeforeCheck=false\npolicyset.caJarSigningSet.2.constraint.params.range=2922\npolicyset.caJarSigningSet.2.default.class_id=validityDefaultImpl\npolicyset.caJarSigningSet.2.default.name=Validity Default\npolicyset.caJarSigningSet.2.default.params.range=1461\npolicyset.caJarSigningSet.2.default.params.startTime=0\npolicyset.caJarSigningSet.3.constraint.class_id=keyConstraintImpl\npolicyset.caJarSigningSet.3.constraint.name=Key Constraint\npolicyset.caJarSigningSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.caJarSigningSet.3.constraint.params.keyType=RSA\npolicyset.caJarSigningSet.3.default.class_id=userKeyDefaultImpl\npolicyset.caJarSigningSet.3.default.name=Key Default\npolicyset.caJarSigningSet.4.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.caJarSigningSet.4.constraint.name=Key Usage Extension Constraint\npolicyset.caJarSigningSet.4.constraint.params.keyUsageCritical=-\npolicyset.caJarSigningSet.4.constraint.params.keyUsageCrlSign=-\npolicyset.caJarSigningSet.4.constraint.params.keyUsageDataEncipherment=-\npolicyset.caJarSigningSet.4.constraint.params.keyUsageDecipherOnly=-\npolicyset.caJarSigningSet.4.constraint.params.keyUsageDigitalSignature=-\npolicyset.caJarSigningSet.4.constraint.params.keyUsageEncipherOnly=-\npolicyset.caJarSigningSet.4.constraint.params.keyUsageKeyAgreement=-\npolicyset.caJarSigningSet.4.constraint.params.keyUsageKeyCertSign=-\npolicyset.caJarSigningSet.4.constraint.params.keyUsageKeyEncipherment=-\npolicyset.caJarSigningSet.4.constraint.params.keyUsageNonRepudiation=-\npolicyset.caJarSigningSet.4.default.class_id=keyUsageExtDefaultImpl\npolicyset.caJarSigningSet.4.default.name=Key Usage Default\npolicyset.caJarSigningSet.4.default.params.keyUsageCritical=true\npolicyset.caJarSigningSet.4.default.params.keyUsageCrlSign=false\npolicyset.caJarSigningSet.4.default.params.keyUsageDataEncipherment=false\npolicyset.caJarSigningSet.4.default.params.keyUsageDecipherOnly=false\npolicyset.caJarSigningSet.4.default.params.keyUsageDigitalSignature=true\npolicyset.caJarSigningSet.4.default.params.keyUsageEncipherOnly=false\npolicyset.caJarSigningSet.4.default.params.keyUsageKeyAgreement=false\npolicyset.caJarSigningSet.4.default.params.keyUsageKeyCertSign=true\npolicyset.caJarSigningSet.4.default.params.keyUsageKeyEncipherment=false\npolicyset.caJarSigningSet.4.default.params.keyUsageNonRepudiation=false\npolicyset.caJarSigningSet.5.constraint.class_id=nsCertTypeExtConstraintImpl\npolicyset.caJarSigningSet.5.constraint.name=Netscape Certificate Type Extension Constraint\npolicyset.caJarSigningSet.5.constraint.params.nsCertCritical=-\npolicyset.caJarSigningSet.5.constraint.params.nsCertEmail=-\npolicyset.caJarSigningSet.5.constraint.params.nsCertEmailCA=-\npolicyset.caJarSigningSet.5.constraint.params.nsCertObjectSigning=-\npolicyset.caJarSigningSet.5.constraint.params.nsCertObjectSigningCA=-\npolicyset.caJarSigningSet.5.constraint.params.nsCertSSLCA=-\npolicyset.caJarSigningSet.5.constraint.params.nsCertSSLClient=-\npolicyset.caJarSigningSet.5.constraint.params.nsCertSSLServer=-\npolicyset.caJarSigningSet.5.default.class_id=nsCertTypeExtDefaultImpl\npolicyset.caJarSigningSet.5.default.name=Netscape Certificate Type Extension Default\npolicyset.caJarSigningSet.5.default.params.nsCertCritical=false\npolicyset.caJarSigningSet.5.default.params.nsCertEmail=false\npolicyset.caJarSigningSet.5.default.params.nsCertEmailCA=false\npolicyset.caJarSigningSet.5.default.params.nsCertObjectSigning=true\npolicyset.caJarSigningSet.5.default.params.nsCertObjectSigningCA=false\npolicyset.caJarSigningSet.5.default.params.nsCertSSLCA=false\npolicyset.caJarSigningSet.5.default.params.nsCertSSLClient=false\npolicyset.caJarSigningSet.5.default.params.nsCertSSLServer=false\npolicyset.caJarSigningSet.6.constraint.class_id=signingAlgConstraintImpl\npolicyset.caJarSigningSet.6.constraint.name=No Constraint\npolicyset.caJarSigningSet.6.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.caJarSigningSet.6.default.class_id=signingAlgDefaultImpl\npolicyset.caJarSigningSet.6.default.name=Signing Alg\npolicyset.caJarSigningSet.6.default.params.signingAlg=-\nprofileId=caJarSigningCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:21Z DEBUG response status 409 2020-06-17T10:09:21Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:21Z DEBUG Error migrating 'caJarSigningCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:21Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caJarSigningCert?action=enable 2020-06-17T10:09:21Z DEBUG request body '' 2020-06-17T10:09:21Z DEBUG response status 409 2020-06-17T10:09:21Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:21Z DEBUG Failed to enable profile 'caJarSigningCert' (it is probably already enabled) 2020-06-17T10:09:21Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:21Z DEBUG request body '' 2020-06-17T10:09:21Z DEBUG response status 204 2020-06-17T10:09:21Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=8E11BCD29A188A36DB24A1AFDA93FB02; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'' 2020-06-17T10:09:21Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:21Z DEBUG request body '' 2020-06-17T10:09:21Z DEBUG response status 200 2020-06-17T10:09:21Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=B5806D867DF9DBB3B669E0DE7895CCFD; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:21Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:21Z DEBUG request body 'desc=This certificate profile is for enrolling server certificates with IPA-RA agent authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, OU=pki-ipa, O=IPA \npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=731\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=https://ipa.example.com/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\nprofileId=caIPAserviceCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:21Z DEBUG response status 409 2020-06-17T10:09:21Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:21Z DEBUG Error migrating 'caIPAserviceCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:21Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caIPAserviceCert?action=enable 2020-06-17T10:09:21Z DEBUG request body '' 2020-06-17T10:09:21Z DEBUG response status 409 2020-06-17T10:09:21Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:21Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:21Z DEBUG Failed to enable profile 'caIPAserviceCert' (it is probably already enabled) 2020-06-17T10:09:21Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:21Z DEBUG request body '' 2020-06-17T10:09:22Z DEBUG response status 204 2020-06-17T10:09:22Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=070A3FABA47BBAF5CC223D90C27DE67F; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:22Z DEBUG response body (decoded): b'' 2020-06-17T10:09:22Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:22Z DEBUG request body '' 2020-06-17T10:09:22Z DEBUG response status 200 2020-06-17T10:09:22Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=29C11D149A932C2EF5628CD6A9C7088A; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:22Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:22Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:22Z DEBUG request body 'desc=This certificate profile is for enrolling user encryption certificates with option to archive keys.\nvisible=false\nenable=true\nenableBy=admin\nname=Manual User Encryption Certificates Enrollment\nauth.class_id=\ninput.list=i1,i2,i3\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=subjectNameInputImpl\ninput.i3.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=encryptionCertSet\npolicyset.encryptionCertSet.list=1,2,3,4,5,6,7,8,9\npolicyset.encryptionCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.encryptionCertSet.1.constraint.name=Subject Name Constraint\npolicyset.encryptionCertSet.1.constraint.params.pattern=CN=.*\npolicyset.encryptionCertSet.1.constraint.params.accept=true\npolicyset.encryptionCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.encryptionCertSet.1.default.name=Subject Name Default\npolicyset.encryptionCertSet.1.default.params.name=\npolicyset.encryptionCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.encryptionCertSet.2.constraint.name=Validity Constraint\npolicyset.encryptionCertSet.2.constraint.params.range=365\npolicyset.encryptionCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.encryptionCertSet.2.constraint.params.notAfterCheck=false\npolicyset.encryptionCertSet.2.default.class_id=validityDefaultImpl\npolicyset.encryptionCertSet.2.default.name=Validity Default\npolicyset.encryptionCertSet.2.default.params.range=180\npolicyset.encryptionCertSet.2.default.params.startTime=0\npolicyset.encryptionCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.encryptionCertSet.3.constraint.name=Key Constraint\npolicyset.encryptionCertSet.3.constraint.params.keyType=RSA\npolicyset.encryptionCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.encryptionCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.encryptionCertSet.3.default.name=Key Default\npolicyset.encryptionCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.4.constraint.name=No Constraint\npolicyset.encryptionCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.encryptionCertSet.4.default.name=Authority Key Identifier Default\npolicyset.encryptionCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.5.constraint.name=No Constraint\npolicyset.encryptionCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.encryptionCertSet.5.default.name=AIA Extension Default\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.encryptionCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.encryptionCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.encryptionCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.encryptionCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.encryptionCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.encryptionCertSet.6.constraint.params.keyUsageDigitalSignature=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.encryptionCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.encryptionCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.encryptionCertSet.6.default.name=Key Usage Default\npolicyset.encryptionCertSet.6.default.params.keyUsageCritical=true\npolicyset.encryptionCertSet.6.default.params.keyUsageDigitalSignature=false\npolicyset.encryptionCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.encryptionCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.encryptionCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.encryptionCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.encryptionCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.encryptionCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.encryptionCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.encryptionCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.encryptionCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.7.constraint.name=No Constraint\npolicyset.encryptionCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.encryptionCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.encryptionCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.encryptionCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.encryptionCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.8.constraint.name=No Constraint\npolicyset.encryptionCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.encryptionCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.encryptionCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.encryptionCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.encryptionCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.encryptionCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.encryptionCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.encryptionCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.encryptionCertSet.9.constraint.name=No Constraint\npolicyset.encryptionCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.encryptionCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.encryptionCertSet.9.default.name=Signing Alg\npolicyset.encryptionCertSet.9.default.params.signingAlg=-\n\nprofileId=caEncUserCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:22Z DEBUG response status 409 2020-06-17T10:09:22Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:22Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:22Z DEBUG Error migrating 'caEncUserCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:22Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caEncUserCert?action=enable 2020-06-17T10:09:22Z DEBUG request body '' 2020-06-17T10:09:22Z DEBUG response status 409 2020-06-17T10:09:22Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:22Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:22Z DEBUG Failed to enable profile 'caEncUserCert' (it is probably already enabled) 2020-06-17T10:09:22Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:22Z DEBUG request body '' 2020-06-17T10:09:22Z DEBUG response status 204 2020-06-17T10:09:22Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=85FE49D5F8FCC0052AA9B20399CB9702; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:22Z DEBUG response body (decoded): b'' 2020-06-17T10:09:22Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:22Z DEBUG request body '' 2020-06-17T10:09:22Z DEBUG response status 200 2020-06-17T10:09:22Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=6928E5A3A8D74DE4A977238DBD8D0244; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:22Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:22Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:22Z DEBUG request body 'desc=This certificate profile is for enrolling user signing certificates.\nvisible=false\nenable=true\nenableBy=admin\nname=Manual User Signing Certificate Enrollment\nauth.class_id=\ninput.list=i1,i2,i3\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=subjectNameInputImpl\ninput.i3.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=signingCertSet\npolicyset.signingCertSet.list=1,2,3,4,5,6,7,8,9\npolicyset.signingCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.signingCertSet.1.constraint.name=Subject Name Constraint\npolicyset.signingCertSet.1.constraint.params.pattern=CN=.*\npolicyset.signingCertSet.1.constraint.params.accept=true\npolicyset.signingCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.signingCertSet.1.default.name=Subject Name Default\npolicyset.signingCertSet.1.default.params.name=\npolicyset.signingCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.signingCertSet.2.constraint.name=Validity Constraint\npolicyset.signingCertSet.2.constraint.params.range=365\npolicyset.signingCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.signingCertSet.2.constraint.params.notAfterCheck=false\npolicyset.signingCertSet.2.default.class_id=validityDefaultImpl\npolicyset.signingCertSet.2.default.name=Validity Default\npolicyset.signingCertSet.2.default.params.range=180\npolicyset.signingCertSet.2.default.params.startTime=0\npolicyset.signingCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.signingCertSet.3.constraint.name=Key Constraint\npolicyset.signingCertSet.3.constraint.params.keyType=RSA\npolicyset.signingCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.signingCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.signingCertSet.3.default.name=Key Default\npolicyset.signingCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.4.constraint.name=No Constraint\npolicyset.signingCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.signingCertSet.4.default.name=Authority Key Identifier Default\npolicyset.signingCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.5.constraint.name=No Constraint\npolicyset.signingCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.signingCertSet.5.default.name=AIA Extension Default\npolicyset.signingCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.signingCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.signingCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.signingCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.signingCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.signingCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.signingCertSet.6.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.6.constraint.name=No Constraint\npolicyset.signingCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.signingCertSet.6.default.name=Key Usage Default\npolicyset.signingCertSet.6.default.params.keyUsageCritical=true\npolicyset.signingCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.signingCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.signingCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.signingCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.signingCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.signingCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.signingCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.signingCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.signingCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.signingCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.7.constraint.name=No Constraint\npolicyset.signingCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.signingCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.signingCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.signingCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.signingCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.8.constraint.name=No Constraint\npolicyset.signingCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.signingCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.signingCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.signingCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.signingCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.signingCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.signingCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.signingCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.signingCertSet.9.constraint.name=No Constraint\npolicyset.signingCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.signingCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.signingCertSet.9.default.name=Signing Alg\npolicyset.signingCertSet.9.default.params.signingAlg=-\n\nprofileId=caSigningUserCert\nclassId=caEnrollImpl\n' 2020-06-17T10:09:22Z DEBUG response status 409 2020-06-17T10:09:22Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:22Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:22Z DEBUG Error migrating 'caSigningUserCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:22Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caSigningUserCert?action=enable 2020-06-17T10:09:22Z DEBUG request body '' 2020-06-17T10:09:22Z DEBUG response status 409 2020-06-17T10:09:22Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:22Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:22Z DEBUG Failed to enable profile 'caSigningUserCert' (it is probably already enabled) 2020-06-17T10:09:22Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:22Z DEBUG request body '' 2020-06-17T10:09:22Z DEBUG response status 204 2020-06-17T10:09:22Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=891D1E590F39761AB5DCB5B602337603; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:21 GMT 2020-06-17T10:09:22Z DEBUG response body (decoded): b'' 2020-06-17T10:09:22Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:22Z DEBUG request body '' 2020-06-17T10:09:22Z DEBUG response status 200 2020-06-17T10:09:22Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=261615095F3A8FDA013819CA9F942548; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:22 GMT 2020-06-17T10:09:22Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:22Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:22Z DEBUG request body 'desc=This profile is for enrolling Token User Delegate Authentication key\nenable=true\nenableBy=admin\nname=Token User Delegate Authentication Certificate Enrollment\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1,i2,i3\ninput.i1.class_id=nsNKeyCertReqInputImpl\ninput.i1.name=nsNKeyCertReqInputImpl\ninput.i2.class_id=subjectDNInputImpl\ninput.i2.name=subjectDNInputImpl\ninput.i3.class_id=subjectAltNameExtInputImpl\ninput.i3.name=subjectAltNameExtInputImpl\noutput.list=o1\noutput.o1.class_id=nsNKeyOutputImpl\noutput.o1.name=nsNKeyOutputImpl\npolicyset.list=set1\n#policyset.set1.list=p2,p4,p5,p1,p6,p7,p8,p9,p12,p13,p14\npolicyset.set1.list=p2,p4,p5,p1,p6,p8,p9,p12\npolicyset.set1.p1.constraint.class_id=subjectNameConstraintImpl\npolicyset.set1.p1.constraint.name=Subject Name Constraint\npolicyset.set1.p1.constraint.params.pattern=.*\npolicyset.set1.p1.constraint.params.accept=true\npolicyset.set1.p1.default.class_id=userSubjectNameDefaultImpl\npolicyset.set1.p1.default.name=Subject Name Default\npolicyset.set1.p1.default.params.name=\n#changed ldap.enable to true to support SMIME\npolicyset.set1.p1.default.params.ldap.enable=false\npolicyset.set1.p1.default.params.ldap.searchName=uid\npolicyset.set1.p1.default.params.ldapStringAttributes=uid,mail\npolicyset.set1.p1.default.params.ldap.basedn=\npolicyset.set1.p1.default.params.ldap.maxConns=4\npolicyset.set1.p1.default.params.ldap.minConns=1\npolicyset.set1.p1.default.params.ldap.ldapconn.Version=2\npolicyset.set1.p1.default.params.ldap.ldapconn.host=\npolicyset.set1.p1.default.params.ldap.ldapconn.port=\npolicyset.set1.p1.default.params.ldap.ldapconn.secureConn=false\npolicyset.set1.p2.constraint.class_id=noConstraintImpl\npolicyset.set1.p2.constraint.name=No Constraint\npolicyset.set1.p2.default.class_id=validityDefaultImpl\npolicyset.set1.p2.default.name=Validity Default\npolicyset.set1.p2.default.params.range=1825\npolicyset.set1.p2.default.params.startTime=0\npolicyset.set1.p4.constraint.class_id=noConstraintImpl\npolicyset.set1.p4.constraint.name=No Constraint\npolicyset.set1.p4.default.class_id=signingAlgDefaultImpl\npolicyset.set1.p4.default.name=Signing Algorithm Default\npolicyset.set1.p4.default.params.signingAlg=-\npolicyset.set1.p5.constraint.class_id=noConstraintImpl\npolicyset.set1.p5.constraint.name=No Constraint\npolicyset.set1.p5.default.class_id=keyUsageExtDefaultImpl\npolicyset.set1.p5.default.name=Key Usage Extension Default\npolicyset.set1.p5.default.params.keyUsageCritical=true\npolicyset.set1.p5.default.params.keyUsageCrlSign=false\npolicyset.set1.p5.default.params.keyUsageDataEncipherment=false\npolicyset.set1.p5.default.params.keyUsageDecipherOnly=false\npolicyset.set1.p5.default.params.keyUsageDigitalSignature=true\npolicyset.set1.p5.default.params.keyUsageEncipherOnly=false\npolicyset.set1.p5.default.params.keyUsageKeyAgreement=false\npolicyset.set1.p5.default.params.keyUsageKeyCertSign=false\npolicyset.set1.p5.default.params.keyUsageKeyEncipherment=false\npolicyset.set1.p5.default.params.keyUsageNonRepudiation=true\npolicyset.set1.p6.constraint.class_id=noConstraintImpl\npolicyset.set1.p6.constraint.name=No Constraint\npolicyset.set1.p6.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.set1.p6.default.name=Subject Alternative Name Extension Default\npolicyset.set1.p6.default.params.subjAltExtGNEnable_0=true\npolicyset.set1.p6.default.params.subjAltExtGNEnable_1=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_2=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_3=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_4=false\npolicyset.set1.p6.default.params.subjAltExtPattern_0=(UTF8String)1.3.6.1.4.1.311.20.2.3,$request.req_san_pattern_0$\npolicyset.set1.p6.default.params.subjAltExtPattern_1=\npolicyset.set1.p6.default.params.subjAltExtPattern_2=\npolicyset.set1.p6.default.params.subjAltExtPattern_3=\npolicyset.set1.p6.default.params.subjAltExtPattern_4=\npolicyset.set1.p6.default.params.subjAltExtType_0=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_1=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_2=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_3=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_4=RFC822Name\npolicyset.set1.p6.default.params.subjAltNameExtCritical=false\npolicyset.set1.p6.default.params.subjAltNameNumGNs=1\npolicyset.set1.p7.constraint.class_id=noConstraintImpl\npolicyset.set1.p7.constraint.name=No Constraint\npolicyset.set1.p7.default.class_id=certificatePoliciesExtDefaultImpl\npolicyset.set1.p7.default.name=Certificate Policies Extension Default\npolicyset.set1.p7.default.params.Critical=false\npolicyset.set1.p7.default.params.PoliciesExt.num=5\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.enable=true\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p8.constraint.class_id=noConstraintImpl\npolicyset.set1.p8.constraint.name=No Constraint\npolicyset.set1.p8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.set1.p8.default.name=Subject Key Identifier Default\npolicyset.set1.p9.constraint.class_id=noConstraintImpl\npolicyset.set1.p9.constraint.name=No Constraint\npolicyset.set1.p9.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.set1.p9.default.name=Authority Key Identifier Extension Default\npolicyset.set1.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.set1.10.constraint.name=Renewal Grace Period Constraint\npolicyset.set1.10.constraint.params.renewal.graceBefore=30\npolicyset.set1.10.constraint.params.renewal.graceAfter=30\npolicyset.set1.10.default.class_id=noDefaultImpl\npolicyset.set1.10.default.name=No Default\npolicyset.set1.p12.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.set1.p12.constraint.name=Basic Constraints Extension Constraint\npolicyset.set1.p12.constraint.params.basicConstraintsCritical=-\npolicyset.set1.p12.constraint.params.basicConstraintsIsCA=-\npolicyset.set1.p12.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.set1.p12.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.set1.p12.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.set1.p12.default.name=Basic Constraints Extension Default\npolicyset.set1.p12.default.params.basicConstraintsCritical=false\npolicyset.set1.p12.default.params.basicConstraintsIsCA=false\npolicyset.set1.p12.default.params.basicConstraintsPathLen=-1\npolicyset.set1.p13.constraint.class_id=noConstraintImpl\npolicyset.set1.p13.constraint.name=No Constraint\npolicyset.set1.p13.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.name=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.params.crlDistPointsCritical=false\npolicyset.set1.p13.default.params.crlDistPointsNum=1\npolicyset.set1.p13.default.params.crlDistPointsEnable_0=false\npolicyset.set1.p13.default.params.crlDistPointsIssuerName_0=\npolicyset.set1.p13.default.params.crlDistPointsIssuerType_0=\npolicyset.set1.p13.default.params.crlDistPointsPointName_0=\npolicyset.set1.p13.default.params.crlDistPointsPointType_0=URIName\npolicyset.set1.p13.default.params.crlDistPointsReasons_0=\npolicyset.set1.p14.constraint.class_id=noConstraintImpl\npolicyset.set1.p14.constraint.name=No Constraint\npolicyset.set1.p14.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.set1.p14.default.name=AIA Extension Default\npolicyset.set1.p14.default.params.authInfoAccessADEnable_0=false\npolicyset.set1.p14.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.set1.p14.default.params.authInfoAccessADLocation_0=\npolicyset.set1.p14.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.set1.p14.default.params.authInfoAccessCritical=false\npolicyset.set1.p14.default.params.authInfoAccessNumADs=1\nprofileId=caTokenUserDelegateAuthKeyEnrollment\nclassId=caUserCertEnrollImpl\n' 2020-06-17T10:09:22Z DEBUG response status 409 2020-06-17T10:09:22Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:22 GMT 2020-06-17T10:09:22Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:22Z DEBUG Error migrating 'caTokenUserDelegateAuthKeyEnrollment': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:22Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caTokenUserDelegateAuthKeyEnrollment?action=enable 2020-06-17T10:09:22Z DEBUG request body '' 2020-06-17T10:09:22Z DEBUG response status 409 2020-06-17T10:09:22Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:22 GMT 2020-06-17T10:09:22Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:22Z DEBUG Failed to enable profile 'caTokenUserDelegateAuthKeyEnrollment' (it is probably already enabled) 2020-06-17T10:09:22Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:22Z DEBUG request body '' 2020-06-17T10:09:22Z DEBUG response status 204 2020-06-17T10:09:22Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=59F7895EA16D518A867FD7A321196E9E; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:22 GMT 2020-06-17T10:09:22Z DEBUG response body (decoded): b'' 2020-06-17T10:09:22Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:22Z DEBUG request body '' 2020-06-17T10:09:22Z DEBUG response status 200 2020-06-17T10:09:22Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=FCDF392AA66CACBF69FFD94E2D24AB44; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:22 GMT 2020-06-17T10:09:22Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:22Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:22Z DEBUG request body 'desc=This profile is for enrolling Token User Delegate Signing key\nenable=true\nenableBy=admin\nname=Token User Delegate Signing Certificate Enrollment\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1,i2,i3\ninput.i1.class_id=nsNKeyCertReqInputImpl\ninput.i1.name=nsNKeyCertReqInputImpl\ninput.i2.class_id=subjectDNInputImpl\ninput.i2.name=subjectDNInputImpl\ninput.i3.class_id=subjectAltNameExtInputImpl\ninput.i3.name=subjectAltNameExtInputImpl\noutput.list=o1\noutput.o1.class_id=nsNKeyOutputImpl\noutput.o1.name=nsNKeyOutputImpl\npolicyset.list=set1\n#policyset.set1.list=p2,p4,p5,p1,p6,p7,p8,p9,p12,p13,p14\npolicyset.set1.list=p2,p4,p5,p1,p6,p8,p9,p12\npolicyset.set1.p1.constraint.class_id=subjectNameConstraintImpl\npolicyset.set1.p1.constraint.name=Subject Name Constraint\npolicyset.set1.p1.constraint.params.pattern=.*\npolicyset.set1.p1.constraint.params.accept=true\npolicyset.set1.p1.default.class_id=userSubjectNameDefaultImpl\npolicyset.set1.p1.default.name=Subject Name Default\npolicyset.set1.p1.default.params.dnpattern=UID=$request.uid$, O=Token Key User\n#changed ldap.enable to true to support SMIME\npolicyset.set1.p1.default.params.ldap.enable=false\npolicyset.set1.p1.default.params.ldap.searchName=uid\npolicyset.set1.p1.default.params.ldapStringAttributes=uid,mail\npolicyset.set1.p1.default.params.ldap.basedn=\npolicyset.set1.p1.default.params.ldap.maxConns=4\npolicyset.set1.p1.default.params.ldap.minConns=1\npolicyset.set1.p1.default.params.ldap.ldapconn.Version=2\npolicyset.set1.p1.default.params.ldap.ldapconn.host=\npolicyset.set1.p1.default.params.ldap.ldapconn.port=\npolicyset.set1.p1.default.params.ldap.ldapconn.secureConn=false\npolicyset.set1.p2.constraint.class_id=noConstraintImpl\npolicyset.set1.p2.constraint.name=No Constraint\npolicyset.set1.p2.default.class_id=validityDefaultImpl\npolicyset.set1.p2.default.name=Validity Default\npolicyset.set1.p2.default.params.range=1825\npolicyset.set1.p2.default.params.startTime=0\npolicyset.set1.p4.constraint.class_id=noConstraintImpl\npolicyset.set1.p4.constraint.name=No Constraint\npolicyset.set1.p4.default.class_id=signingAlgDefaultImpl\npolicyset.set1.p4.default.name=Signing Algorithm Default\npolicyset.set1.p4.default.params.signingAlg=-\npolicyset.set1.p5.constraint.class_id=noConstraintImpl\npolicyset.set1.p5.constraint.name=No Constraint\npolicyset.set1.p5.default.class_id=keyUsageExtDefaultImpl\npolicyset.set1.p5.default.name=Key Usage Extension Default\npolicyset.set1.p5.default.params.keyUsageCritical=true\npolicyset.set1.p5.default.params.keyUsageCrlSign=false\npolicyset.set1.p5.default.params.keyUsageDataEncipherment=false\npolicyset.set1.p5.default.params.keyUsageDecipherOnly=false\npolicyset.set1.p5.default.params.keyUsageDigitalSignature=true\npolicyset.set1.p5.default.params.keyUsageEncipherOnly=false\npolicyset.set1.p5.default.params.keyUsageKeyAgreement=false\npolicyset.set1.p5.default.params.keyUsageKeyCertSign=false\npolicyset.set1.p5.default.params.keyUsageKeyEncipherment=false\npolicyset.set1.p5.default.params.keyUsageNonRepudiation=true\npolicyset.set1.p6.constraint.class_id=noConstraintImpl\npolicyset.set1.p6.constraint.name=No Constraint\npolicyset.set1.p6.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.set1.p6.default.name=Subject Alternative Name Extension Default\npolicyset.set1.p6.default.params.subjAltExtGNEnable_0=true\npolicyset.set1.p6.default.params.subjAltExtGNEnable_1=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_2=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_3=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_4=false\npolicyset.set1.p6.default.params.subjAltExtPattern_0=$request.req_san_pattern_0$\npolicyset.set1.p6.default.params.subjAltExtPattern_1=\npolicyset.set1.p6.default.params.subjAltExtPattern_2=\npolicyset.set1.p6.default.params.subjAltExtPattern_3=\npolicyset.set1.p6.default.params.subjAltExtPattern_4=\npolicyset.set1.p6.default.params.subjAltExtType_0=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_1=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_2=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_3=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_4=RFC822Name\npolicyset.set1.p6.default.params.subjAltNameExtCritical=false\npolicyset.set1.p6.default.params.subjAltNameNumGNs=1\npolicyset.set1.p7.constraint.class_id=noConstraintImpl\npolicyset.set1.p7.constraint.name=No Constraint\npolicyset.set1.p7.default.class_id=certificatePoliciesExtDefaultImpl\npolicyset.set1.p7.default.name=Certificate Policies Extension Default\npolicyset.set1.p7.default.params.Critical=false\npolicyset.set1.p7.default.params.PoliciesExt.num=5\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.enable=true\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p8.constraint.class_id=noConstraintImpl\npolicyset.set1.p8.constraint.name=No Constraint\npolicyset.set1.p8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.set1.p8.default.name=Subject Key Identifier Default\npolicyset.set1.p9.constraint.class_id=noConstraintImpl\npolicyset.set1.p9.constraint.name=No Constraint\npolicyset.set1.p9.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.set1.p9.default.name=Authority Key Identifier Extension Default\npolicyset.set1.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.set1.10.constraint.name=Renewal Grace Period Constraint\npolicyset.set1.10.constraint.params.renewal.graceBefore=30\npolicyset.set1.10.constraint.params.renewal.graceAfter=30\npolicyset.set1.10.default.class_id=noDefaultImpl\npolicyset.set1.10.default.name=No Default\npolicyset.set1.p12.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.set1.p12.constraint.name=Basic Constraints Extension Constraint\npolicyset.set1.p12.constraint.params.basicConstraintsCritical=-\npolicyset.set1.p12.constraint.params.basicConstraintsIsCA=-\npolicyset.set1.p12.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.set1.p12.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.set1.p12.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.set1.p12.default.name=Basic Constraints Extension Default\npolicyset.set1.p12.default.params.basicConstraintsCritical=false\npolicyset.set1.p12.default.params.basicConstraintsIsCA=false\npolicyset.set1.p12.default.params.basicConstraintsPathLen=-1\npolicyset.set1.p13.constraint.class_id=noConstraintImpl\npolicyset.set1.p13.constraint.name=No Constraint\npolicyset.set1.p13.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.name=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.params.crlDistPointsCritical=false\npolicyset.set1.p13.default.params.crlDistPointsNum=1\npolicyset.set1.p13.default.params.crlDistPointsEnable_0=false\npolicyset.set1.p13.default.params.crlDistPointsIssuerName_0=\npolicyset.set1.p13.default.params.crlDistPointsIssuerType_0=\npolicyset.set1.p13.default.params.crlDistPointsPointName_0=\npolicyset.set1.p13.default.params.crlDistPointsPointType_0=URIName\npolicyset.set1.p13.default.params.crlDistPointsReasons_0=\npolicyset.set1.p14.constraint.class_id=noConstraintImpl\npolicyset.set1.p14.constraint.name=No Constraint\npolicyset.set1.p14.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.set1.p14.default.name=AIA Extension Default\npolicyset.set1.p14.default.params.authInfoAccessADEnable_0=false\npolicyset.set1.p14.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.set1.p14.default.params.authInfoAccessADLocation_0=\npolicyset.set1.p14.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.set1.p14.default.params.authInfoAccessCritical=false\npolicyset.set1.p14.default.params.authInfoAccessNumADs=1\nprofileId=caTokenUserDelegateSigningKeyEnrollment\nclassId=caUserCertEnrollImpl\n' 2020-06-17T10:09:22Z DEBUG response status 409 2020-06-17T10:09:22Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:22 GMT 2020-06-17T10:09:22Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:22Z DEBUG Error migrating 'caTokenUserDelegateSigningKeyEnrollment': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:22Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caTokenUserDelegateSigningKeyEnrollment?action=enable 2020-06-17T10:09:22Z DEBUG request body '' 2020-06-17T10:09:22Z DEBUG response status 409 2020-06-17T10:09:22Z DEBUG response headers Content-Type: application/xml;charset=UTF-8 Content-Length: 233 Date: Wed, 17 Jun 2020 10:09:22 GMT 2020-06-17T10:09:22Z DEBUG response body (decoded): b'com.netscape.certsrv.base.ConflictingOperationException409Profile already enabled' 2020-06-17T10:09:22Z DEBUG Failed to enable profile 'caTokenUserDelegateSigningKeyEnrollment' (it is probably already enabled) 2020-06-17T10:09:22Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:22Z DEBUG request body '' 2020-06-17T10:09:22Z DEBUG response status 204 2020-06-17T10:09:22Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=0F43160ED2EBCFB637DEF48A2A2F8F8E; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:22 GMT 2020-06-17T10:09:22Z DEBUG response body (decoded): b'' 2020-06-17T10:09:22Z DEBUG step duration: pki-tomcatd migrate_profiles_to_ldap 15.77 sec 2020-06-17T10:09:22Z DEBUG [26/29]: importing IPA certificate profiles 2020-06-17T10:09:22Z DEBUG Created connection context.ldap2_139849942905128 2020-06-17T10:09:22Z DEBUG Created connection context.ldap2_139849942195784 2020-06-17T10:09:22Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:09:22Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:09:22Z DEBUG Destroyed connection context.ldap2_139849942195784 2020-06-17T10:09:22Z DEBUG Created connection context.ldap2_139849942192648 2020-06-17T10:09:22Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:09:22Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:09:23Z DEBUG Destroyed connection context.ldap2_139849942192648 2020-06-17T10:09:23Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:09:23Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:09:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:09:23Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:09:23Z DEBUG Trying to find certificate subject base in sysupgrade 2020-06-17T10:09:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:09:23Z DEBUG Found certificate subject base in sysupgrade: O=LIN.TEST.LAN 2020-06-17T10:09:23Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:23Z DEBUG request body '' 2020-06-17T10:09:23Z DEBUG response status 200 2020-06-17T10:09:23Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=21B11ABB7FBFD1F747930301F3D320D2; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:22 GMT 2020-06-17T10:09:23Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:23Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:23Z DEBUG request body 'profileId=IECUserRoles\nclassId=caEnrollImpl\ndesc=Enroll user certificates with IECUserRoles extension via IPA-RA agent authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=LIN.TEST.LAN\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=731\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.lin.test.lan/ca/ocsp\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.lin.test.lan/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.12.default.name=IECUserRoles Extension Default\npolicyset.serverCertSet.12.default.params.userExtOID=1.2.840.10070.8.1\n' 2020-06-17T10:09:23Z DEBUG response status 201 2020-06-17T10:09:23Z DEBUG response headers Location: https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw Content-Type: application/json Content-Length: 7330 Date: Wed, 17 Jun 2020 10:09:22 GMT 2020-06-17T10:09:23Z DEBUG response body (decoded): b'#Wed Jun 17 06:09:23 EDT 2020\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.2.default.params.range=731\ninput.i2.class_id=submitterInfoInputImpl\nauth.instance_id=raCertAuth\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\noutput.o1.class_id=certOutputImpl\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\noutput.list=o1\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\ninput.list=i1,i2\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\nvisible=false\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\ndesc=Enroll user certificates with IECUserRoles extension via IPA-RA agent authentication.\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.lin.test.lan/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\nenable=true\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\ninput.i1.class_id=certReqInputImpl\nenableBy=admin\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11,12\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=LIN.TEST.LAN\npolicyset.serverCertSet.12.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.12.default.params.userExtOID=1.2.840.10070.8.1\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.12.default.name=IECUserRoles Extension Default\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.lin.test.lan/ca/ocsp\n' 2020-06-17T10:09:23Z DEBUG Profile 'IECUserRoles' successfully migrated to LDAP 2020-06-17T10:09:23Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/IECUserRoles?action=enable 2020-06-17T10:09:23Z DEBUG request body '' 2020-06-17T10:09:23Z DEBUG response status 204 2020-06-17T10:09:23Z DEBUG response headers Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:22 GMT 2020-06-17T10:09:23Z DEBUG response body (decoded): b'' 2020-06-17T10:09:23Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:23Z DEBUG request body '' 2020-06-17T10:09:23Z DEBUG response status 204 2020-06-17T10:09:23Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=B6C44D1F9104E2D835C983E4C38968FD; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:23 GMT 2020-06-17T10:09:23Z DEBUG response body (decoded): b'' 2020-06-17T10:09:23Z DEBUG Imported profile 'IECUserRoles' 2020-06-17T10:09:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:09:23Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:09:23Z DEBUG Trying to find certificate subject base in sysupgrade 2020-06-17T10:09:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:09:23Z DEBUG Found certificate subject base in sysupgrade: O=LIN.TEST.LAN 2020-06-17T10:09:23Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:23Z DEBUG request body '' 2020-06-17T10:09:23Z DEBUG response status 200 2020-06-17T10:09:23Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=EE6C5DD4CFEA2D632EBE9F368353B8E9; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:23 GMT 2020-06-17T10:09:23Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:23Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:23Z DEBUG request body 'profileId=KDCs_PKINIT_Certs\nclassId=caEnrollImpl\ndesc=This certificate profile is for enrolling server certificates with IPA-RA agent authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=LIN.TEST.LAN\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=731\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.lin.test.lan/ca/ocsp\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.2.3.5\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.lin.test.lan/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\n' 2020-06-17T10:09:23Z DEBUG response status 201 2020-06-17T10:09:23Z DEBUG response headers Location: https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw Content-Type: application/json Content-Length: 6976 Date: Wed, 17 Jun 2020 10:09:23 GMT 2020-06-17T10:09:23Z DEBUG response body (decoded): b'#Wed Jun 17 06:09:23 EDT 2020\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.2.3.5\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.2.default.params.range=731\ninput.i2.class_id=submitterInfoInputImpl\nauth.instance_id=raCertAuth\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\noutput.o1.class_id=certOutputImpl\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\noutput.list=o1\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\ninput.list=i1,i2\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\nvisible=false\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\ndesc=This certificate profile is for enrolling server certificates with IPA-RA agent authentication.\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.lin.test.lan/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\nenable=true\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.3.constraint.params.keyParameters=2048,3072,4096\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\ninput.i1.class_id=certReqInputImpl\nenableBy=admin\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=LIN.TEST.LAN\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.lin.test.lan/ca/ocsp\n' 2020-06-17T10:09:23Z DEBUG Profile 'KDCs_PKINIT_Certs' successfully migrated to LDAP 2020-06-17T10:09:23Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/KDCs_PKINIT_Certs?action=enable 2020-06-17T10:09:23Z DEBUG request body '' 2020-06-17T10:09:23Z DEBUG response status 204 2020-06-17T10:09:23Z DEBUG response headers Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:23 GMT 2020-06-17T10:09:23Z DEBUG response body (decoded): b'' 2020-06-17T10:09:23Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:23Z DEBUG request body '' 2020-06-17T10:09:23Z DEBUG response status 204 2020-06-17T10:09:23Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=023B447F170A19B6A43CB66E79C4DD92; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:23 GMT 2020-06-17T10:09:23Z DEBUG response body (decoded): b'' 2020-06-17T10:09:23Z DEBUG Imported profile 'KDCs_PKINIT_Certs' 2020-06-17T10:09:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:09:23Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:09:23Z DEBUG Trying to find certificate subject base in sysupgrade 2020-06-17T10:09:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:09:23Z DEBUG Found certificate subject base in sysupgrade: O=LIN.TEST.LAN 2020-06-17T10:09:23Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:23Z DEBUG request body '' 2020-06-17T10:09:23Z DEBUG response status 200 2020-06-17T10:09:23Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=C87DADB40D4FCC5043B2ED1EAA6FF15A; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:23 GMT 2020-06-17T10:09:23Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:23Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/raw 2020-06-17T10:09:23Z DEBUG request body 'profileId=caIPAserviceCert\nclassId=caEnrollImpl\ndesc=This certificate profile is for enrolling server certificates with IPA-RA agent authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=LIN.TEST.LAN\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=731\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,8192\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.lin.test.lan/ca/ocsp\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.lin.test.lan/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name\n' 2020-06-17T10:09:23Z DEBUG response status 409 2020-06-17T10:09:23Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Wed, 17 Jun 2020 10:09:23 GMT 2020-06-17T10:09:23Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2020-06-17T10:09:23Z DEBUG Error migrating 'caIPAserviceCert': Request failed with status 409: Réponse non 2xx reçue de l'API REST de l'AC : 409. Unable to create profile: Profile already exists 2020-06-17T10:09:23Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caIPAserviceCert?action=disable 2020-06-17T10:09:23Z DEBUG request body '' 2020-06-17T10:09:23Z DEBUG response status 204 2020-06-17T10:09:23Z DEBUG response headers Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:23 GMT 2020-06-17T10:09:23Z DEBUG response body (decoded): b'' 2020-06-17T10:09:23Z DEBUG request PUT https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caIPAserviceCert/raw 2020-06-17T10:09:23Z DEBUG request body 'profileId=caIPAserviceCert\nclassId=caEnrollImpl\ndesc=This certificate profile is for enrolling server certificates with IPA-RA agent authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=LIN.TEST.LAN\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=731\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,8192\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.lin.test.lan/ca/ocsp\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.lin.test.lan/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name\n' 2020-06-17T10:09:23Z DEBUG response status 200 2020-06-17T10:09:23Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Content-Type: application/json Content-Length: 7290 Date: Wed, 17 Jun 2020 10:09:23 GMT 2020-06-17T10:09:23Z DEBUG response body (decoded): b'#Wed Jun 17 06:09:23 EDT 2020\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.2.default.params.range=731\ninput.i2.class_id=submitterInfoInputImpl\nauth.instance_id=raCertAuth\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\noutput.o1.class_id=certOutputImpl\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\noutput.list=o1\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\ninput.list=i1,i2\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\nvisible=false\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\ndesc=This certificate profile is for enrolling server certificates with IPA-RA agent authentication.\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.lin.test.lan/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\nenable=true\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,8192\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\ninput.i1.class_id=certReqInputImpl\nenableBy=admin\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11,12\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=LIN.TEST.LAN\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.lin.test.lan/ca/ocsp\n' 2020-06-17T10:09:23Z DEBUG request POST https://freeipaserver.lin.test.lan:8443/ca/rest/profiles/caIPAserviceCert?action=enable 2020-06-17T10:09:23Z DEBUG request body '' 2020-06-17T10:09:24Z DEBUG response status 204 2020-06-17T10:09:24Z DEBUG response headers Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:23 GMT 2020-06-17T10:09:24Z DEBUG response body (decoded): b'' 2020-06-17T10:09:24Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:24Z DEBUG request body '' 2020-06-17T10:09:24Z DEBUG response status 204 2020-06-17T10:09:24Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=0B898682F15869986CEF106E4CA8B717; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:23 GMT 2020-06-17T10:09:24Z DEBUG response body (decoded): b'' 2020-06-17T10:09:24Z DEBUG Imported profile 'caIPAserviceCert' 2020-06-17T10:09:24Z DEBUG Destroyed connection context.ldap2_139849942905128 2020-06-17T10:09:24Z DEBUG step duration: pki-tomcatd import_included_profiles 1.36 sec 2020-06-17T10:09:24Z DEBUG [27/29]: adding default CA ACL 2020-06-17T10:09:24Z DEBUG Created connection context.ldap2_139849947500496 2020-06-17T10:09:24Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:09:24Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:09:24Z DEBUG Destroyed connection context.ldap2_139849947500496 2020-06-17T10:09:24Z DEBUG Created connection context.ldap2_139849947500048 2020-06-17T10:09:24Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:09:24Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:09:24Z DEBUG Destroyed connection context.ldap2_139849947500048 2020-06-17T10:09:24Z DEBUG raw: caacl_find(None, version='2.235') 2020-06-17T10:09:24Z DEBUG caacl_find(None, all=False, raw=False, version='2.235', no_members=True, pkey_only=False) 2020-06-17T10:09:24Z DEBUG raw: caacl_add('hosts_services_caIPAserviceCert', hostcategory='all', servicecategory='all', version='2.235') 2020-06-17T10:09:24Z DEBUG caacl_add('hosts_services_caIPAserviceCert', hostcategory='all', servicecategory='all', all=False, raw=False, version='2.235', no_members=False) 2020-06-17T10:09:24Z DEBUG raw: caacl_add_profile('hosts_services_caIPAserviceCert', version='2.235', certprofile=('caIPAserviceCert',)) 2020-06-17T10:09:24Z DEBUG caacl_add_profile('hosts_services_caIPAserviceCert', all=False, raw=False, version='2.235', no_members=False, certprofile=('caIPAserviceCert',)) 2020-06-17T10:09:24Z DEBUG add_entry_to_group: dn=cn=caIPAserviceCert,cn=certprofiles,cn=ca,dc=lin,dc=test,dc=lan group_dn=ipaUniqueID=9ec5b530-b082-11ea-8acc-525400885899,cn=caacls,cn=ca,dc=lin,dc=test,dc=lan member_attr=ipamembercertprofile 2020-06-17T10:09:24Z DEBUG step duration: pki-tomcatd ensure_default_caacl 0.38 sec 2020-06-17T10:09:24Z DEBUG [28/29]: adding 'ipa' CA entry 2020-06-17T10:09:24Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/login 2020-06-17T10:09:24Z DEBUG request body '' 2020-06-17T10:09:24Z DEBUG response status 200 2020-06-17T10:09:24Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=2FCC21F7DD7D7FBEA06B268A6DA42200; Path=/ca; Secure; HttpOnly Content-Type: application/xml;charset=UTF-8 Content-Length: 218 Date: Wed, 17 Jun 2020 10:09:24 GMT 2020-06-17T10:09:24Z DEBUG response body (decoded): b'iparaCertificate Manager AgentsRegistration Manager Agents' 2020-06-17T10:09:24Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/authorities/host-authority 2020-06-17T10:09:24Z DEBUG request body '' 2020-06-17T10:09:24Z DEBUG response status 200 2020-06-17T10:09:24Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Content-Type: application/json Content-Length: 266 Date: Wed, 17 Jun 2020 10:09:24 GMT 2020-06-17T10:09:24Z DEBUG response body (decoded): b'{"isHostAuthority":true,"id":"02c4ae19-bea1-4408-b30c-6933e157b939","parentID":null,"issuerDN":"CN=Certificate Authority,O=LIN.TEST.LAN","serial":1,"dn":"CN=Certificate Authority,O=LIN.TEST.LAN","enabled":true,"description":"Host authority","ready":true,"link":null}' 2020-06-17T10:09:24Z DEBUG request GET https://freeipaserver.lin.test.lan:8443/ca/rest/account/logout 2020-06-17T10:09:24Z DEBUG request body '' 2020-06-17T10:09:24Z DEBUG response status 204 2020-06-17T10:09:24Z DEBUG response headers Cache-Control: private Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID=0E21AFB4F40DBE826E5A72CDDECFF532; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Wed, 17 Jun 2020 10:09:24 GMT 2020-06-17T10:09:24Z DEBUG response body (decoded): b'' 2020-06-17T10:09:24Z DEBUG Created connection context.ldap2_139849948199232 2020-06-17T10:09:24Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:09:24Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:09:24Z DEBUG Destroyed connection context.ldap2_139849948199232 2020-06-17T10:09:24Z DEBUG Created connection context.ldap2_139849948070016 2020-06-17T10:09:24Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:09:24Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:09:25Z DEBUG Destroyed connection context.ldap2_139849948070016 2020-06-17T10:09:25Z DEBUG step duration: pki-tomcatd ensure_ipa_authority_entry 0.66 sec 2020-06-17T10:09:25Z DEBUG [29/29]: configuring certmonger renewal for lightweight CAs 2020-06-17T10:09:25Z DEBUG step duration: pki-tomcatd add_lightweight_ca_tracking_requests 0.00 sec 2020-06-17T10:09:25Z DEBUG Done configuring certificate server (pki-tomcatd). 2020-06-17T10:09:25Z DEBUG service duration: pki-tomcatd 178.50 sec 2020-06-17T10:09:25Z DEBUG Removing /root/.dogtag/pki-tomcat/ca 2020-06-17T10:09:25Z DEBUG Configuring directory server (dirsrv) 2020-06-17T10:09:25Z DEBUG [1/3]: configuring TLS for DS instance 2020-06-17T10:09:25Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:09:25Z DEBUG Starting external process 2020-06-17T10:09:25Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-LIN-TEST-LAN/', '-L', '-n', 'LIN.TEST.LAN IPA CA', '-a', '-f', '/etc/dirsrv/slapd-LIN-TEST-LAN/pwdfile.txt'] 2020-06-17T10:09:25Z DEBUG Process finished, return code=255 2020-06-17T10:09:25Z DEBUG stdout= 2020-06-17T10:09:25Z DEBUG stderr=certutil: Could not find cert: LIN.TEST.LAN IPA CA : PR_FILE_NOT_FOUND_ERROR: File not found 2020-06-17T10:09:25Z DEBUG Starting external process 2020-06-17T10:09:25Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-LIN-TEST-LAN/', '-N', '-f', '/etc/dirsrv/slapd-LIN-TEST-LAN/pwdfile.txt', '-@', '/etc/dirsrv/slapd-LIN-TEST-LAN/pwdfile.txt'] 2020-06-17T10:09:25Z DEBUG Process finished, return code=0 2020-06-17T10:09:25Z DEBUG stdout= 2020-06-17T10:09:25Z DEBUG stderr= 2020-06-17T10:09:25Z DEBUG Starting external process 2020-06-17T10:09:25Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T10:09:25Z DEBUG Process finished, return code=0 2020-06-17T10:09:25Z DEBUG stdout= 2020-06-17T10:09:25Z DEBUG stderr= 2020-06-17T10:09:25Z DEBUG Starting external process 2020-06-17T10:09:25Z DEBUG args=['/sbin/restorecon', '-F', '/etc/dirsrv/slapd-LIN-TEST-LAN/'] 2020-06-17T10:09:25Z DEBUG Process finished, return code=0 2020-06-17T10:09:25Z DEBUG stdout= 2020-06-17T10:09:25Z DEBUG stderr= 2020-06-17T10:09:25Z DEBUG Starting external process 2020-06-17T10:09:25Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T10:09:25Z DEBUG Process finished, return code=0 2020-06-17T10:09:25Z DEBUG stdout= 2020-06-17T10:09:25Z DEBUG stderr= 2020-06-17T10:09:25Z DEBUG Starting external process 2020-06-17T10:09:25Z DEBUG args=['/sbin/restorecon', '-F', '/etc/dirsrv/slapd-LIN-TEST-LAN/cert9.db'] 2020-06-17T10:09:25Z DEBUG Process finished, return code=0 2020-06-17T10:09:25Z DEBUG stdout= 2020-06-17T10:09:25Z DEBUG stderr= 2020-06-17T10:09:25Z DEBUG Starting external process 2020-06-17T10:09:25Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T10:09:25Z DEBUG Process finished, return code=0 2020-06-17T10:09:25Z DEBUG stdout= 2020-06-17T10:09:25Z DEBUG stderr= 2020-06-17T10:09:25Z DEBUG Starting external process 2020-06-17T10:09:25Z DEBUG args=['/sbin/restorecon', '-F', '/etc/dirsrv/slapd-LIN-TEST-LAN/key4.db'] 2020-06-17T10:09:25Z DEBUG Process finished, return code=0 2020-06-17T10:09:25Z DEBUG stdout= 2020-06-17T10:09:25Z DEBUG stderr= 2020-06-17T10:09:25Z DEBUG Starting external process 2020-06-17T10:09:25Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T10:09:25Z DEBUG Process finished, return code=0 2020-06-17T10:09:25Z DEBUG stdout= 2020-06-17T10:09:25Z DEBUG stderr= 2020-06-17T10:09:25Z DEBUG Starting external process 2020-06-17T10:09:25Z DEBUG args=['/sbin/restorecon', '-F', '/etc/dirsrv/slapd-LIN-TEST-LAN/pkcs11.txt'] 2020-06-17T10:09:25Z DEBUG Process finished, return code=0 2020-06-17T10:09:25Z DEBUG stdout= 2020-06-17T10:09:25Z DEBUG stderr= 2020-06-17T10:09:25Z DEBUG Starting external process 2020-06-17T10:09:25Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T10:09:25Z DEBUG Process finished, return code=0 2020-06-17T10:09:25Z DEBUG stdout= 2020-06-17T10:09:25Z DEBUG stderr= 2020-06-17T10:09:25Z DEBUG Starting external process 2020-06-17T10:09:25Z DEBUG args=['/sbin/restorecon', '-F', '/etc/dirsrv/slapd-LIN-TEST-LAN/pwdfile.txt'] 2020-06-17T10:09:25Z DEBUG Process finished, return code=0 2020-06-17T10:09:25Z DEBUG stdout= 2020-06-17T10:09:25Z DEBUG stderr= 2020-06-17T10:09:25Z DEBUG Starting external process 2020-06-17T10:09:25Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-LIN-TEST-LAN/', '-A', '-n', 'LIN.TEST.LAN IPA CA', '-t', 'CT,C,C', '-a', '-f', '/etc/dirsrv/slapd-LIN-TEST-LAN/pwdfile.txt'] 2020-06-17T10:09:25Z DEBUG Process finished, return code=0 2020-06-17T10:09:25Z DEBUG stdout= 2020-06-17T10:09:25Z DEBUG stderr= 2020-06-17T10:09:25Z DEBUG certmonger request is in state dbus.String('NEWLY_ADDED_READING_KEYINFO', variant_level=1) 2020-06-17T10:09:30Z DEBUG certmonger request is in state dbus.String('POST_SAVED_CERT', variant_level=1) 2020-06-17T10:09:35Z DEBUG certmonger request is in state dbus.String('MONITORING', variant_level=1) 2020-06-17T10:09:35Z DEBUG Cert request 20200617100925 was successful 2020-06-17T10:09:35Z DEBUG Destroyed connection context.ldap2_139850008098072 2020-06-17T10:09:35Z DEBUG Created connection context.ldap2_139850008098072 2020-06-17T10:09:35Z DEBUG Starting external process 2020-06-17T10:09:35Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-LIN-TEST-LAN/', '-L', '-n', 'Server-Cert', '-a', '-f', '/etc/dirsrv/slapd-LIN-TEST-LAN/pwdfile.txt'] 2020-06-17T10:09:35Z DEBUG Process finished, return code=0 2020-06-17T10:09:35Z DEBUG stdout=-----BEGIN CERTIFICATE----- MIIFUTCCA7mgAwIBAgIBCDANBgkqhkiG9w0BAQsFADA3MRUwEwYDVQQKDAxMSU4u VEVTVC5MQU4xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMDA2 MTcxMDA5MjZaFw0yMjA2MTgxMDA5MjZaMDwxFTATBgNVBAoMDExJTi5URVNULkxB TjEjMCEGA1UEAwwaZnJlZWlwYXNlcnZlci5saW4udGVzdC5sYW4wggEiMA0GCSqG SIb3DQEBAQUAA4IBDwAwggEKAoIBAQDXXcwM8r3Rhb9veIJjb2Qs1ygQVfd5XHw3 BxpGdZ2A/e+9LUuoaYLaDsX8Sri67UJpDE1VgeNtuulsUnlFM/uQ++aCllPuAT86 hBX2RqloXJMEtr6m/lLC2SsbEoG464nN7VEGtMLqUZ6xycCPhGhvN1Z/ci5f1sVk +y89kPkDp2D6z/7O60wSu/pkVaqKBnSQDBuJ+0cl3miA+J9OaTmb3hwGQPgCIaTN 40Bc+jMW4V4ua1RuaiyjMOuPHySpLQL6Xa8eD7SMKGcIAGOPvdDCaMvJxpz9cgue y3XrVmsKdpwRy83N3ljv2OtEnHYZjgkGKwREtKLxHEiI37QoC6lvAgMBAAGjggHh MIIB3TAfBgNVHSMEGDAWgBRRNzUgAs0oE7FW88XDJYUgXwd5HjA+BggrBgEFBQcB AQQyMDAwLgYIKwYBBQUHMAGGImh0dHA6Ly9pcGEtY2EubGluLnRlc3QubGFuL2Nh L29jc3AwDgYDVR0PAQH/BAQDAgTwMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEF BQcDAjB3BgNVHR8EcDBuMGygNKAyhjBodHRwOi8vaXBhLWNhLmxpbi50ZXN0Lmxh bi9pcGEvY3JsL01hc3RlckNSTC5iaW6iNKQyMDAxDjAMBgNVBAoMBWlwYWNhMR4w HAYDVQQDDBVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHQYDVR0OBBYEFE4CgUEvUj4t 3ncK31OQQaXgla4+MIGyBgNVHREEgaowgaeCGmZyZWVpcGFzZXJ2ZXIubGluLnRl c3QubGFuoDwGCisGAQQBgjcUAgOgLgwsbGRhcC9mcmVlaXBhc2VydmVyLmxpbi50 ZXN0LmxhbkBMSU4uVEVTVC5MQU6gSwYGKwYBBQICoEEwP6AOGwxMSU4uVEVTVC5M QU6hLTAroAMCAQGhJDAiGwRsZGFwGxpmcmVlaXBhc2VydmVyLmxpbi50ZXN0Lmxh bjANBgkqhkiG9w0BAQsFAAOCAYEAlfft4Bgfm8dWhfjG7/AuAthDDd1J3i+FMIT0 9iWVk4xnQmBnVUI7mFo07I/9yVQ2tQi0MGFFCI++CiKlYMkLaFeGP+FD4zxBqDBb xngoNjL3yEtR8VeWykTyBcyi1EbZekPaXRnAo2Lj3thr90WCG/XutIDid8XwQ7IU kM8RZ2Jb9hgkeFU6h4LgqYKHxrvKB7HPyJmtuPW8+w7bPn8NuFVSyEGhlGXAv1nM 3HfP4U7yAYQXtPb0BXDXFQipkg0ePDflJEf/q3gdkLv3HTYS7dEKPbgMyqXsCgBZ 5fEgpaEzcgZii73HRceeivdBLUK1niFwc4oji8WpwJTRf4jX+NkVlXbrd97BiYoN SlPMdYzCVla6Hv/lzhO1ua3LlnZtCEcpFHWOpmAqAKhgAu55S3yH1W2McRJhtAAl ShbqdwCfPzGAUke5mQgXxQUln9HJAMSttPzuqt2hj8zmEXn8KDK1e6dNIX+hLXoc rmifKVFqBaP5RE/idhL0lDsuRXBP -----END CERTIFICATE----- 2020-06-17T10:09:35Z DEBUG stderr= 2020-06-17T10:09:35Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:09:35Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:09:36Z DEBUG step duration: dirsrv __enable_ssl 11.17 sec 2020-06-17T10:09:36Z DEBUG [2/3]: adding CA certificate entry 2020-06-17T10:09:36Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:09:36Z DEBUG Starting external process 2020-06-17T10:09:36Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-LIN-TEST-LAN/', '-L', '-f', '/etc/dirsrv/slapd-LIN-TEST-LAN/pwdfile.txt'] 2020-06-17T10:09:36Z DEBUG Process finished, return code=0 2020-06-17T10:09:36Z DEBUG stdout= Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI LIN.TEST.LAN IPA CA CT,C,C Server-Cert u,u,u 2020-06-17T10:09:36Z DEBUG stderr= 2020-06-17T10:09:36Z DEBUG Starting external process 2020-06-17T10:09:36Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-LIN-TEST-LAN/', '-O', '--simple-self-signed', '-n', 'LIN.TEST.LAN IPA CA', '-f', '/etc/dirsrv/slapd-LIN-TEST-LAN/pwdfile.txt'] 2020-06-17T10:09:36Z DEBUG Process finished, return code=0 2020-06-17T10:09:36Z DEBUG stdout="LIN.TEST.LAN IPA CA" [CN=Certificate Authority,O=LIN.TEST.LAN] 2020-06-17T10:09:36Z DEBUG stderr= 2020-06-17T10:09:36Z DEBUG Starting external process 2020-06-17T10:09:36Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-LIN-TEST-LAN/', '-L', '-n', 'LIN.TEST.LAN IPA CA', '-a', '-f', '/etc/dirsrv/slapd-LIN-TEST-LAN/pwdfile.txt'] 2020-06-17T10:09:36Z DEBUG Process finished, return code=0 2020-06-17T10:09:36Z DEBUG stdout=-----BEGIN CERTIFICATE----- MIIEjjCCAvagAwIBAgIBATANBgkqhkiG9w0BAQsFADA3MRUwEwYDVQQKDAxMSU4u VEVTVC5MQU4xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMDA2 MTcxMDA3MjFaFw00MDA2MTcxMDA3MjFaMDcxFTATBgNVBAoMDExJTi5URVNULkxB TjEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MIIBojANBgkqhkiG9w0B AQEFAAOCAY8AMIIBigKCAYEAraJmeLv5JRkWpW+M3y1Yd/BD6atlDnUUrTIUo7rC pGLrBs0Bu1aJWmeMj+tkp5iuC+ah93p9ABctuKAh9s56M4TQlcFcevrzCgE8FClM 5LpK2DkQNuNusopgxqUi/dYKXbdwGO64DqnQiJ5Z8hh1vvc2eeAIkAWThPuxH6UO dbESHS5m55aPhUK17OdvK6ukQxCMbplVH77SRZ0U3lpHzSbXrjKFwlRyEuq1IGAS hrhteZpFtxWl1BmfHmrNcNWUEAfHrhK1vKDBKzV2+u2lnKdASQlX2oPGg1H8Yxoe UO8Rm4eNqlnACv29SL2CHXAVcs1iTNCbTXkIndMhhhdPX/plv4l0JDyHJGwAmQXy K1O4i5OqNLeDt63z7llpxinpN0fev1qQ4q7LFy7+psJ01aP7/AuH/LxAChPnABlY G2Fs307O9lSYhpOrk49U/i/8Xadrc2LoTx8Cbj3kSnA8/FeSR/bVEORwMuYws71c 7dLDbsZUACu0uDsLSx1vikeTAgMBAAGjgaQwgaEwHwYDVR0jBBgwFoAUUTc1IALN KBOxVvPFwyWFIF8HeR4wDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAcYw HQYDVR0OBBYEFFE3NSACzSgTsVbzxcMlhSBfB3keMD4GCCsGAQUFBwEBBDIwMDAu BggrBgEFBQcwAYYiaHR0cDovL2lwYS1jYS5saW4udGVzdC5sYW4vY2Evb2NzcDAN BgkqhkiG9w0BAQsFAAOCAYEAfRexfx4eGi6qS9okGfK/M2PQ++JIj5som4aocW26 HsZcrbT5t/Vo9IYRhTDvq1nkNlHwl8OiiAi0rgJP6TOPbpp3V8mQcRgdXAA06hlb b5TX2KmSMC11rleR7NjeKxyMlTW9YpyBU5WrjL28MMEt9tL6O4lMivA3dXEX2D4u l+7MOURdHx8Gxsz3Sv1AOoZwmL/evGTkURrf1ArfrH3G/IguFKUTSI939s/baIyY MBp6z1VagQeeoCHI7gw5flT5oezeoLp620I4vJ7YH22rrfkHLxL8WZ4NpRqcgKfO fDKVHT28meSAdVajABznAsOq1uYK5yQWhoK8ug9gNCUjrjukh2bb3lOwDVuz7fLS Sr02x6ghisReo7uP0EZ4CajvyhPcVn+rcpL+x/SKd1vK9iN91THTDtC7eYwYNGpG vqMnn7mt+rACtBGneE+/rtmL8YedIyIhrSBtPpDnR4ptglRMyRTs7Fnor0fJ8dDV L0MoRipLMGUN5SDzZ5foD9OU -----END CERTIFICATE----- 2020-06-17T10:09:36Z DEBUG stderr= 2020-06-17T10:09:36Z DEBUG step duration: dirsrv __upload_ca_cert 0.16 sec 2020-06-17T10:09:36Z DEBUG [3/3]: restarting directory server 2020-06-17T10:09:36Z DEBUG Destroyed connection context.ldap2_139850008098072 2020-06-17T10:09:36Z DEBUG Starting external process 2020-06-17T10:09:36Z DEBUG args=['/bin/systemctl', '--system', 'daemon-reload'] 2020-06-17T10:09:36Z DEBUG Process finished, return code=0 2020-06-17T10:09:36Z DEBUG stdout= 2020-06-17T10:09:36Z DEBUG stderr= 2020-06-17T10:09:36Z DEBUG Starting external process 2020-06-17T10:09:36Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:09:39Z DEBUG Process finished, return code=0 2020-06-17T10:09:39Z DEBUG stdout= 2020-06-17T10:09:39Z DEBUG stderr= 2020-06-17T10:09:39Z DEBUG Starting external process 2020-06-17T10:09:39Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:09:39Z DEBUG Process finished, return code=0 2020-06-17T10:09:39Z DEBUG stdout=active 2020-06-17T10:09:39Z DEBUG stderr= 2020-06-17T10:09:39Z DEBUG wait_for_open_ports: localhost [389] timeout 120 2020-06-17T10:09:39Z DEBUG waiting for port: 389 2020-06-17T10:09:39Z DEBUG SUCCESS: port: 389 2020-06-17T10:09:39Z DEBUG Restart of dirsrv@LIN-TEST-LAN.service complete 2020-06-17T10:09:39Z DEBUG Starting external process 2020-06-17T10:09:39Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:09:39Z DEBUG Process finished, return code=0 2020-06-17T10:09:39Z DEBUG stdout=active 2020-06-17T10:09:39Z DEBUG stderr= 2020-06-17T10:09:39Z DEBUG Created connection context.ldap2_139850008098072 2020-06-17T10:09:39Z DEBUG step duration: dirsrv __restart_instance 2.97 sec 2020-06-17T10:09:39Z DEBUG Done configuring directory server (dirsrv). 2020-06-17T10:09:39Z DEBUG service duration: dirsrv 14.30 sec 2020-06-17T10:09:39Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:09:39Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:09:39Z DEBUG Starting external process 2020-06-17T10:09:39Z DEBUG args=['/bin/systemctl', 'stop', 'pki-tomcatd@pki-tomcat.service'] 2020-06-17T10:09:40Z DEBUG Process finished, return code=0 2020-06-17T10:09:40Z DEBUG stdout= 2020-06-17T10:09:40Z DEBUG stderr= 2020-06-17T10:09:40Z DEBUG Stop of pki-tomcatd@pki-tomcat.service complete 2020-06-17T10:09:40Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:09:40Z DEBUG Ensuring that service pki-tomcatd@pki-tomcat is not running while the next set of commands is being executed. 2020-06-17T10:09:40Z DEBUG Starting external process 2020-06-17T10:09:40Z DEBUG args=['/bin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2020-06-17T10:09:40Z DEBUG Process finished, return code=3 2020-06-17T10:09:40Z DEBUG stdout=inactive 2020-06-17T10:09:40Z DEBUG stderr= 2020-06-17T10:09:40Z DEBUG Service pki-tomcatd@pki-tomcat is not running, continue. 2020-06-17T10:09:40Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:09:40Z DEBUG Set up lightweight CA key retrieval 2020-06-17T10:09:40Z DEBUG Creating principal 2020-06-17T10:09:40Z DEBUG Starting external process 2020-06-17T10:09:40Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'addprinc -randkey dogtag/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-x', 'ipa-setup-override-restrictions'] 2020-06-17T10:09:40Z DEBUG Process finished, return code=0 2020-06-17T10:09:40Z DEBUG stdout=Authenticating as principal root/admin@LIN.TEST.LAN with password. Principal "dogtag/freeipaserver.lin.test.lan@LIN.TEST.LAN" created. 2020-06-17T10:09:40Z DEBUG stderr=WARNING: no policy specified for dogtag/freeipaserver.lin.test.lan@LIN.TEST.LAN; defaulting to no policy 2020-06-17T10:09:40Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:09:40Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:09:40Z DEBUG Retrieving keytab 2020-06-17T10:09:40Z DEBUG Starting external process 2020-06-17T10:09:40Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'ktadd -k /etc/pki/pki-tomcat/dogtag.keytab dogtag/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-x', 'ipa-setup-override-restrictions'] 2020-06-17T10:09:41Z DEBUG Process finished, return code=0 2020-06-17T10:09:41Z DEBUG stdout=Authenticating as principal root/admin@LIN.TEST.LAN with password. Entry for principal dogtag/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type aes128-cts-hmac-sha256-128 added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type aes256-cts-hmac-sha384-192 added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. 2020-06-17T10:09:41Z DEBUG stderr= 2020-06-17T10:09:41Z DEBUG Creating Custodia keys 2020-06-17T10:09:41Z DEBUG Created connection context.ldap2_139849980704472 2020-06-17T10:09:41Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:09:41Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:09:41Z DEBUG Destroyed connection context.ldap2_139849980704472 2020-06-17T10:09:41Z DEBUG Created connection context.ldap2_139849980704976 2020-06-17T10:09:41Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:09:41Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:09:41Z DEBUG Destroyed connection context.ldap2_139849980704976 2020-06-17T10:09:41Z DEBUG Configuring key retriever 2020-06-17T10:09:41Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:09:41Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:09:41Z DEBUG Destroyed connection context.ldap2_139850008098072 2020-06-17T10:09:41Z DEBUG Starting external process 2020-06-17T10:09:41Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:09:45Z DEBUG Process finished, return code=0 2020-06-17T10:09:45Z DEBUG stdout= 2020-06-17T10:09:45Z DEBUG stderr= 2020-06-17T10:09:45Z DEBUG Restart of dirsrv@LIN-TEST-LAN.service complete 2020-06-17T10:09:45Z DEBUG Created connection context.ldap2_139850008098072 2020-06-17T10:09:45Z DEBUG Starting external process 2020-06-17T10:09:45Z DEBUG args=['/bin/systemctl', 'start', 'pki-tomcatd@pki-tomcat.service'] 2020-06-17T10:09:59Z DEBUG Process finished, return code=0 2020-06-17T10:09:59Z DEBUG stdout= 2020-06-17T10:09:59Z DEBUG stderr= 2020-06-17T10:09:59Z DEBUG Starting external process 2020-06-17T10:09:59Z DEBUG args=['/bin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2020-06-17T10:09:59Z DEBUG Process finished, return code=0 2020-06-17T10:09:59Z DEBUG stdout=active 2020-06-17T10:09:59Z DEBUG stderr= 2020-06-17T10:09:59Z DEBUG wait_for_open_ports: localhost [8080, 8443] timeout 120 2020-06-17T10:09:59Z DEBUG waiting for port: 8080 2020-06-17T10:09:59Z DEBUG SUCCESS: port: 8080 2020-06-17T10:09:59Z DEBUG waiting for port: 8443 2020-06-17T10:09:59Z DEBUG SUCCESS: port: 8443 2020-06-17T10:09:59Z DEBUG Start of pki-tomcatd@pki-tomcat.service complete 2020-06-17T10:09:59Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:09:59Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:09:59Z DEBUG Configuring ipa-otpd 2020-06-17T10:09:59Z DEBUG [1/2]: starting ipa-otpd 2020-06-17T10:09:59Z DEBUG Starting external process 2020-06-17T10:09:59Z DEBUG args=['/bin/systemctl', 'is-active', 'ipa-otpd.socket'] 2020-06-17T10:09:59Z DEBUG Process finished, return code=3 2020-06-17T10:09:59Z DEBUG stdout=inactive 2020-06-17T10:09:59Z DEBUG stderr= 2020-06-17T10:09:59Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:09:59Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:09:59Z DEBUG Starting external process 2020-06-17T10:09:59Z DEBUG args=['/bin/systemctl', 'restart', 'ipa-otpd.socket'] 2020-06-17T10:09:59Z DEBUG Process finished, return code=0 2020-06-17T10:09:59Z DEBUG stdout= 2020-06-17T10:09:59Z DEBUG stderr= 2020-06-17T10:09:59Z DEBUG Starting external process 2020-06-17T10:09:59Z DEBUG args=['/bin/systemctl', 'is-active', 'ipa-otpd.socket'] 2020-06-17T10:09:59Z DEBUG Process finished, return code=0 2020-06-17T10:09:59Z DEBUG stdout=active 2020-06-17T10:09:59Z DEBUG stderr= 2020-06-17T10:09:59Z DEBUG Restart of ipa-otpd.socket complete 2020-06-17T10:09:59Z DEBUG step duration: ipa-otpd __start 0.06 sec 2020-06-17T10:09:59Z DEBUG [2/2]: configuring ipa-otpd to start on boot 2020-06-17T10:09:59Z DEBUG Starting external process 2020-06-17T10:09:59Z DEBUG args=['/bin/systemctl', 'is-enabled', 'ipa-otpd.socket'] 2020-06-17T10:09:59Z DEBUG Process finished, return code=1 2020-06-17T10:09:59Z DEBUG stdout=disabled 2020-06-17T10:09:59Z DEBUG stderr= 2020-06-17T10:09:59Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:09:59Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:09:59Z DEBUG Starting external process 2020-06-17T10:09:59Z DEBUG args=['/bin/systemctl', 'disable', 'ipa-otpd.socket'] 2020-06-17T10:09:59Z DEBUG Process finished, return code=0 2020-06-17T10:09:59Z DEBUG stdout= 2020-06-17T10:09:59Z DEBUG stderr= 2020-06-17T10:09:59Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:09:59Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:09:59Z DEBUG step duration: ipa-otpd __enable 0.38 sec 2020-06-17T10:09:59Z DEBUG Done configuring ipa-otpd. 2020-06-17T10:09:59Z DEBUG service duration: ipa-otpd 0.44 sec 2020-06-17T10:09:59Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:09:59Z DEBUG Configuring the web interface (httpd) 2020-06-17T10:09:59Z DEBUG [1/21]: stopping httpd 2020-06-17T10:09:59Z DEBUG Starting external process 2020-06-17T10:09:59Z DEBUG args=['/bin/systemctl', 'is-active', 'httpd.service'] 2020-06-17T10:09:59Z DEBUG Process finished, return code=3 2020-06-17T10:09:59Z DEBUG stdout=inactive 2020-06-17T10:09:59Z DEBUG stderr= 2020-06-17T10:09:59Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:09:59Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:09:59Z DEBUG Starting external process 2020-06-17T10:09:59Z DEBUG args=['/bin/systemctl', 'stop', 'httpd.service'] 2020-06-17T10:09:59Z DEBUG Process finished, return code=0 2020-06-17T10:09:59Z DEBUG stdout= 2020-06-17T10:09:59Z DEBUG stderr= 2020-06-17T10:09:59Z DEBUG Stop of httpd.service complete 2020-06-17T10:09:59Z DEBUG step duration: httpd __stop 0.04 sec 2020-06-17T10:09:59Z DEBUG [2/21]: backing up ssl.conf 2020-06-17T10:09:59Z DEBUG Backing up system configuration file '/etc/httpd/conf.d/ssl.conf' 2020-06-17T10:09:59Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:09:59Z DEBUG Backing up system configuration file '/etc/httpd/conf.d/ssl.conf' 2020-06-17T10:09:59Z DEBUG -> Not backing up - already have a copy of '/etc/httpd/conf.d/ssl.conf' 2020-06-17T10:09:59Z DEBUG step duration: httpd backup_ssl_conf 0.00 sec 2020-06-17T10:09:59Z DEBUG [3/21]: disabling nss.conf 2020-06-17T10:09:59Z DEBUG step duration: httpd disable_nss_conf 0.00 sec 2020-06-17T10:09:59Z DEBUG [4/21]: configuring mod_ssl certificate paths 2020-06-17T10:09:59Z DEBUG step duration: httpd configure_mod_ssl_certs 0.00 sec 2020-06-17T10:09:59Z DEBUG [5/21]: setting mod_ssl protocol list 2020-06-17T10:09:59Z DEBUG step duration: httpd set_mod_ssl_protocol 0.00 sec 2020-06-17T10:09:59Z DEBUG [6/21]: configuring mod_ssl log directory 2020-06-17T10:09:59Z DEBUG step duration: httpd set_mod_ssl_logdir 0.00 sec 2020-06-17T10:09:59Z DEBUG [7/21]: disabling mod_ssl OCSP 2020-06-17T10:09:59Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:09:59Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:09:59Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:09:59Z DEBUG step duration: httpd disable_mod_ssl_ocsp 0.02 sec 2020-06-17T10:09:59Z DEBUG [8/21]: adding URL rewriting rules 2020-06-17T10:09:59Z DEBUG step duration: httpd __add_include 0.00 sec 2020-06-17T10:09:59Z DEBUG [9/21]: configuring httpd 2020-06-17T10:09:59Z DEBUG Starting external process 2020-06-17T10:09:59Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T10:09:59Z DEBUG Process finished, return code=0 2020-06-17T10:09:59Z DEBUG stdout= 2020-06-17T10:09:59Z DEBUG stderr= 2020-06-17T10:09:59Z DEBUG Starting external process 2020-06-17T10:09:59Z DEBUG args=['/sbin/restorecon', '/etc/systemd/system/httpd.service.d/ipa.conf'] 2020-06-17T10:09:59Z DEBUG Process finished, return code=0 2020-06-17T10:09:59Z DEBUG stdout= 2020-06-17T10:09:59Z DEBUG stderr= 2020-06-17T10:09:59Z DEBUG Starting external process 2020-06-17T10:09:59Z DEBUG args=['/bin/systemctl', '--system', 'daemon-reload'] 2020-06-17T10:10:00Z DEBUG Process finished, return code=0 2020-06-17T10:10:00Z DEBUG stdout= 2020-06-17T10:10:00Z DEBUG stderr= 2020-06-17T10:10:00Z INFO Nothing to do for configure_httpd_wsgi_conf 2020-06-17T10:10:00Z DEBUG Starting external process 2020-06-17T10:10:00Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T10:10:00Z DEBUG Process finished, return code=0 2020-06-17T10:10:00Z DEBUG stdout= 2020-06-17T10:10:00Z DEBUG stderr= 2020-06-17T10:10:00Z DEBUG Starting external process 2020-06-17T10:10:00Z DEBUG args=['/sbin/restorecon', '/etc/httpd/alias'] 2020-06-17T10:10:00Z DEBUG Process finished, return code=0 2020-06-17T10:10:00Z DEBUG stdout= 2020-06-17T10:10:00Z DEBUG stderr= 2020-06-17T10:10:00Z DEBUG Backing up system configuration file '/etc/httpd/conf.d/ipa.conf' 2020-06-17T10:10:00Z DEBUG -> Not backing up - '/etc/httpd/conf.d/ipa.conf' doesn't exist 2020-06-17T10:10:00Z DEBUG Backing up system configuration file '/etc/httpd/conf.d/ipa-rewrite.conf' 2020-06-17T10:10:00Z DEBUG -> Not backing up - '/etc/httpd/conf.d/ipa-rewrite.conf' doesn't exist 2020-06-17T10:10:00Z DEBUG step duration: httpd __configure_http 0.23 sec 2020-06-17T10:10:00Z DEBUG [10/21]: setting up httpd keytab 2020-06-17T10:10:00Z DEBUG raw: service_add('HTTP/freeipaserver.lin.test.lan@LIN.TEST.LAN', force=True, version='2.235') 2020-06-17T10:10:00Z DEBUG service_add(ipapython.kerberos.Principal('HTTP/freeipaserver.lin.test.lan@LIN.TEST.LAN'), force=True, skip_host_check=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T10:10:00Z DEBUG raw: host_show('freeipaserver.lin.test.lan', version='2.235') 2020-06-17T10:10:00Z DEBUG host_show('freeipaserver.lin.test.lan', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T10:10:00Z DEBUG Backing up system configuration file '/var/lib/ipa/gssproxy/http.keytab' 2020-06-17T10:10:00Z DEBUG -> Not backing up - '/var/lib/ipa/gssproxy/http.keytab' doesn't exist 2020-06-17T10:10:00Z DEBUG Starting external process 2020-06-17T10:10:00Z DEBUG args=['/usr/sbin/ipa-getkeytab', '-k', '/var/lib/ipa/gssproxy/http.keytab', '-p', 'HTTP/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:10:00Z DEBUG Process finished, return code=0 2020-06-17T10:10:00Z DEBUG stdout= 2020-06-17T10:10:00Z DEBUG stderr=Récupération du tableau de clés et stockage avec succès dans : /var/lib/ipa/gssproxy/http.keytab 2020-06-17T10:10:00Z DEBUG step duration: httpd request_service_keytab 0.10 sec 2020-06-17T10:10:00Z DEBUG [11/21]: configuring Gssproxy 2020-06-17T10:10:00Z DEBUG Starting external process 2020-06-17T10:10:00Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T10:10:00Z DEBUG Process finished, return code=0 2020-06-17T10:10:00Z DEBUG stdout= 2020-06-17T10:10:00Z DEBUG stderr= 2020-06-17T10:10:00Z DEBUG Starting external process 2020-06-17T10:10:00Z DEBUG args=['/sbin/restorecon', '/etc/gssproxy/10-ipa.conf'] 2020-06-17T10:10:00Z DEBUG Process finished, return code=0 2020-06-17T10:10:00Z DEBUG stdout= 2020-06-17T10:10:00Z DEBUG stderr= 2020-06-17T10:10:00Z DEBUG Starting external process 2020-06-17T10:10:00Z DEBUG args=['/bin/systemctl', 'restart', 'gssproxy.service'] 2020-06-17T10:10:00Z DEBUG Process finished, return code=0 2020-06-17T10:10:00Z DEBUG stdout= 2020-06-17T10:10:00Z DEBUG stderr= 2020-06-17T10:10:00Z DEBUG Starting external process 2020-06-17T10:10:00Z DEBUG args=['/bin/systemctl', 'is-active', 'gssproxy.service'] 2020-06-17T10:10:00Z DEBUG Process finished, return code=0 2020-06-17T10:10:00Z DEBUG stdout=active 2020-06-17T10:10:00Z DEBUG stderr= 2020-06-17T10:10:00Z DEBUG Restart of gssproxy.service complete 2020-06-17T10:10:00Z DEBUG step duration: httpd configure_gssproxy 0.09 sec 2020-06-17T10:10:00Z DEBUG [12/21]: setting up ssl 2020-06-17T10:10:00Z DEBUG certmonger request is in state dbus.String('NEWLY_ADDED_READING_KEYINFO', variant_level=1) 2020-06-17T10:10:05Z DEBUG certmonger request is in state dbus.String('MONITORING', variant_level=1) 2020-06-17T10:10:05Z DEBUG Cert request 20200617101000 was successful 2020-06-17T10:10:06Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:10:06Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:10:06Z DEBUG step duration: httpd __setup_ssl 5.81 sec 2020-06-17T10:10:06Z DEBUG [13/21]: configure certmonger for renewals 2020-06-17T10:10:06Z DEBUG Starting external process 2020-06-17T10:10:06Z DEBUG args=['/bin/systemctl', 'is-active', 'certmonger.service'] 2020-06-17T10:10:06Z DEBUG Process finished, return code=0 2020-06-17T10:10:06Z DEBUG stdout=active 2020-06-17T10:10:06Z DEBUG stderr= 2020-06-17T10:10:06Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:10:06Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:10:06Z DEBUG step duration: httpd configure_certmonger_renewal_guard 0.47 sec 2020-06-17T10:10:06Z DEBUG [14/21]: publish CA cert 2020-06-17T10:10:06Z DEBUG step duration: httpd __publish_ca_cert 0.01 sec 2020-06-17T10:10:06Z DEBUG [15/21]: clean up any existing httpd ccaches 2020-06-17T10:10:06Z DEBUG step duration: httpd remove_httpd_ccaches 0.00 sec 2020-06-17T10:10:06Z DEBUG [16/21]: configuring SELinux for httpd 2020-06-17T10:10:06Z DEBUG Starting external process 2020-06-17T10:10:06Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T10:10:06Z DEBUG Process finished, return code=0 2020-06-17T10:10:06Z DEBUG stdout= 2020-06-17T10:10:06Z DEBUG stderr= 2020-06-17T10:10:06Z DEBUG Starting external process 2020-06-17T10:10:06Z DEBUG args=['/usr/sbin/getsebool', 'httpd_can_network_connect'] 2020-06-17T10:10:06Z DEBUG Process finished, return code=0 2020-06-17T10:10:06Z DEBUG stdout=httpd_can_network_connect --> off 2020-06-17T10:10:06Z DEBUG stderr= 2020-06-17T10:10:06Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:10:06Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:10:06Z DEBUG Starting external process 2020-06-17T10:10:06Z DEBUG args=['/usr/sbin/getsebool', 'httpd_manage_ipa'] 2020-06-17T10:10:06Z DEBUG Process finished, return code=0 2020-06-17T10:10:06Z DEBUG stdout=httpd_manage_ipa --> off 2020-06-17T10:10:06Z DEBUG stderr= 2020-06-17T10:10:06Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:10:06Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:10:06Z DEBUG Starting external process 2020-06-17T10:10:06Z DEBUG args=['/usr/sbin/getsebool', 'httpd_run_ipa'] 2020-06-17T10:10:06Z DEBUG Process finished, return code=0 2020-06-17T10:10:06Z DEBUG stdout=httpd_run_ipa --> off 2020-06-17T10:10:06Z DEBUG stderr= 2020-06-17T10:10:06Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:10:06Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:10:06Z DEBUG Starting external process 2020-06-17T10:10:06Z DEBUG args=['/usr/sbin/getsebool', 'httpd_dbus_sssd'] 2020-06-17T10:10:07Z DEBUG Process finished, return code=0 2020-06-17T10:10:07Z DEBUG stdout=httpd_dbus_sssd --> off 2020-06-17T10:10:07Z DEBUG stderr= 2020-06-17T10:10:07Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:10:07Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:10:07Z DEBUG Starting external process 2020-06-17T10:10:07Z DEBUG args=['/usr/sbin/setsebool', '-P', 'httpd_can_network_connect=on', 'httpd_manage_ipa=on', 'httpd_run_ipa=on', 'httpd_dbus_sssd=on'] 2020-06-17T10:10:31Z DEBUG Process finished, return code=0 2020-06-17T10:10:31Z DEBUG stdout= 2020-06-17T10:10:31Z DEBUG stderr= 2020-06-17T10:10:31Z DEBUG step duration: httpd configure_selinux_for_httpd 25.33 sec 2020-06-17T10:10:31Z DEBUG [17/21]: create KDC proxy config 2020-06-17T10:10:31Z DEBUG Backing up system configuration file '/etc/ipa/kdcproxy/ipa-kdc-proxy.conf' 2020-06-17T10:10:31Z DEBUG -> Not backing up - '/etc/ipa/kdcproxy/ipa-kdc-proxy.conf' doesn't exist 2020-06-17T10:10:31Z DEBUG step duration: httpd create_kdcproxy_conf 0.00 sec 2020-06-17T10:10:31Z DEBUG [18/21]: enable KDC proxy 2020-06-17T10:10:31Z DEBUG service KDC has all config values set 2020-06-17T10:10:31Z DEBUG step duration: httpd enable_kdcproxy 0.03 sec 2020-06-17T10:10:31Z DEBUG [19/21]: starting httpd 2020-06-17T10:10:31Z DEBUG Starting external process 2020-06-17T10:10:31Z DEBUG args=['/bin/systemctl', 'start', 'httpd.service'] 2020-06-17T10:10:32Z DEBUG Process finished, return code=0 2020-06-17T10:10:32Z DEBUG stdout= 2020-06-17T10:10:32Z DEBUG stderr= 2020-06-17T10:10:32Z DEBUG Starting external process 2020-06-17T10:10:32Z DEBUG args=['/bin/systemctl', 'is-active', 'httpd.service'] 2020-06-17T10:10:32Z DEBUG Process finished, return code=0 2020-06-17T10:10:32Z DEBUG stdout=active 2020-06-17T10:10:32Z DEBUG stderr= 2020-06-17T10:10:32Z DEBUG Start of httpd.service complete 2020-06-17T10:10:32Z DEBUG step duration: httpd start 0.78 sec 2020-06-17T10:10:32Z DEBUG [20/21]: configuring httpd to start on boot 2020-06-17T10:10:32Z DEBUG Starting external process 2020-06-17T10:10:32Z DEBUG args=['/bin/systemctl', 'is-enabled', 'httpd.service'] 2020-06-17T10:10:32Z DEBUG Process finished, return code=1 2020-06-17T10:10:32Z DEBUG stdout=disabled 2020-06-17T10:10:32Z DEBUG stderr= 2020-06-17T10:10:32Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:10:32Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:10:33Z DEBUG Starting external process 2020-06-17T10:10:33Z DEBUG args=['/bin/systemctl', 'disable', 'httpd.service'] 2020-06-17T10:10:34Z DEBUG Process finished, return code=0 2020-06-17T10:10:34Z DEBUG stdout= 2020-06-17T10:10:34Z DEBUG stderr= 2020-06-17T10:10:34Z DEBUG step duration: httpd __enable 1.81 sec 2020-06-17T10:10:34Z DEBUG [21/21]: enabling oddjobd 2020-06-17T10:10:34Z DEBUG Starting external process 2020-06-17T10:10:34Z DEBUG args=['/bin/systemctl', 'is-active', 'oddjobd.service'] 2020-06-17T10:10:34Z DEBUG Process finished, return code=3 2020-06-17T10:10:34Z DEBUG stdout=inactive 2020-06-17T10:10:34Z DEBUG stderr= 2020-06-17T10:10:34Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:10:34Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:10:34Z DEBUG Starting external process 2020-06-17T10:10:34Z DEBUG args=['/bin/systemctl', 'is-enabled', 'oddjobd.service'] 2020-06-17T10:10:34Z DEBUG Process finished, return code=1 2020-06-17T10:10:34Z DEBUG stdout=disabled 2020-06-17T10:10:34Z DEBUG stderr= 2020-06-17T10:10:34Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:10:34Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:10:34Z DEBUG Starting external process 2020-06-17T10:10:34Z DEBUG args=['/bin/systemctl', 'enable', 'oddjobd.service'] 2020-06-17T10:10:35Z DEBUG Process finished, return code=0 2020-06-17T10:10:35Z DEBUG stdout= 2020-06-17T10:10:35Z DEBUG stderr=Created symlink /etc/systemd/system/multi-user.target.wants/oddjobd.service → /usr/lib/systemd/system/oddjobd.service. 2020-06-17T10:10:35Z DEBUG Starting external process 2020-06-17T10:10:35Z DEBUG args=['/bin/systemctl', 'start', 'oddjobd.service'] 2020-06-17T10:10:35Z DEBUG Process finished, return code=0 2020-06-17T10:10:35Z DEBUG stdout= 2020-06-17T10:10:35Z DEBUG stderr= 2020-06-17T10:10:35Z DEBUG Starting external process 2020-06-17T10:10:35Z DEBUG args=['/bin/systemctl', 'is-active', 'oddjobd.service'] 2020-06-17T10:10:35Z DEBUG Process finished, return code=0 2020-06-17T10:10:35Z DEBUG stdout=active 2020-06-17T10:10:35Z DEBUG stderr= 2020-06-17T10:10:35Z DEBUG Start of oddjobd.service complete 2020-06-17T10:10:35Z DEBUG step duration: httpd enable_and_start_oddjobd 1.10 sec 2020-06-17T10:10:35Z DEBUG Done configuring the web interface (httpd). 2020-06-17T10:10:35Z DEBUG service duration: httpd 35.82 sec 2020-06-17T10:10:35Z DEBUG Configuring Kerberos KDC (krb5kdc) 2020-06-17T10:10:35Z DEBUG [1/1]: installing X509 Certificate for PKINIT 2020-06-17T10:10:37Z DEBUG certmonger request is in state dbus.String('NEWLY_ADDED_READING_KEYINFO', variant_level=1) 2020-06-17T10:10:42Z DEBUG certmonger request is in state dbus.String('MONITORING', variant_level=1) 2020-06-17T10:10:42Z DEBUG Cert request 20200617101037 was successful 2020-06-17T10:10:43Z DEBUG service KDC has all config values set 2020-06-17T10:10:43Z DEBUG step duration: krb5kdc setup_pkinit 7.44 sec 2020-06-17T10:10:43Z DEBUG Done configuring Kerberos KDC (krb5kdc). 2020-06-17T10:10:43Z DEBUG service duration: krb5kdc 7.44 sec 2020-06-17T10:10:43Z DEBUG Starting external process 2020-06-17T10:10:43Z DEBUG args=['/bin/systemctl', 'restart', 'krb5kdc.service'] 2020-06-17T10:10:43Z DEBUG Process finished, return code=0 2020-06-17T10:10:43Z DEBUG stdout= 2020-06-17T10:10:43Z DEBUG stderr= 2020-06-17T10:10:43Z DEBUG Starting external process 2020-06-17T10:10:43Z DEBUG args=['/bin/systemctl', 'is-active', 'krb5kdc.service'] 2020-06-17T10:10:44Z DEBUG Process finished, return code=0 2020-06-17T10:10:44Z DEBUG stdout=active 2020-06-17T10:10:44Z DEBUG stderr= 2020-06-17T10:10:44Z DEBUG Restart of krb5kdc.service complete 2020-06-17T10:10:44Z DEBUG Applying LDAP updates 2020-06-17T10:10:44Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:10:44Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:10:44Z DEBUG Starting external process 2020-06-17T10:10:44Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:10:44Z DEBUG Process finished, return code=0 2020-06-17T10:10:44Z DEBUG stdout=active 2020-06-17T10:10:44Z DEBUG stderr= 2020-06-17T10:10:44Z DEBUG Upgrading IPA:. Estimated time: 1 minute 30 seconds 2020-06-17T10:10:44Z DEBUG [1/10]: stopping directory server 2020-06-17T10:10:44Z DEBUG Destroyed connection context.ldap2_139850008098072 2020-06-17T10:10:44Z DEBUG Starting external process 2020-06-17T10:10:44Z DEBUG args=['/bin/systemctl', 'stop', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:10:47Z DEBUG Process finished, return code=0 2020-06-17T10:10:47Z DEBUG stdout= 2020-06-17T10:10:47Z DEBUG stderr= 2020-06-17T10:10:47Z DEBUG Stop of dirsrv@LIN-TEST-LAN.service complete 2020-06-17T10:10:47Z DEBUG step duration: dirsrv __stop_instance 3.20 sec 2020-06-17T10:10:47Z DEBUG [2/10]: saving configuration 2020-06-17T10:10:48Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:10:48Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:10:48Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:10:48Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:10:48Z DEBUG step duration: dirsrv __save_config 1.12 sec 2020-06-17T10:10:48Z DEBUG [3/10]: disabling listeners 2020-06-17T10:10:49Z DEBUG step duration: dirsrv __disable_listeners 0.41 sec 2020-06-17T10:10:49Z DEBUG [4/10]: enabling DS global lock 2020-06-17T10:10:49Z DEBUG step duration: dirsrv __enable_ds_global_write_lock 0.45 sec 2020-06-17T10:10:49Z DEBUG [5/10]: disabling Schema Compat 2020-06-17T10:10:49Z DEBUG step duration: dirsrv __disable_schema_compat 0.27 sec 2020-06-17T10:10:49Z DEBUG [6/10]: starting directory server 2020-06-17T10:10:49Z DEBUG Starting external process 2020-06-17T10:10:49Z DEBUG args=['/bin/systemctl', 'start', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:10:51Z DEBUG Process finished, return code=0 2020-06-17T10:10:51Z DEBUG stdout= 2020-06-17T10:10:51Z DEBUG stderr= 2020-06-17T10:10:51Z DEBUG Start of dirsrv@LIN-TEST-LAN.service complete 2020-06-17T10:10:51Z DEBUG Created connection context.ldap2_139850008098072 2020-06-17T10:10:51Z DEBUG step duration: dirsrv __start 1.61 sec 2020-06-17T10:10:51Z DEBUG [7/10]: upgrading server 2020-06-17T10:10:51Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.aci 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.automember 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.automount 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-06-17T10:10:51Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.batch 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.ca 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.cert 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.config 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.dns 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.group 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-06-17T10:10:51Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.host 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.internal 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.join 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.location 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.migration 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.misc 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.otp 2020-06-17T10:10:51Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.permission 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.ping 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-06-17T10:10:51Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.role 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.schema 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.server 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.service 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.session 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-06-17T10:10:51Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.topology 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.trust 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.user 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.vault 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-06-17T10:10:51Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-06-17T10:10:51Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.install.plugins.dns 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2020-06-17T10:10:51Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2020-06-17T10:10:52Z DEBUG Created connection context.ldap2_139849980197240 2020-06-17T10:10:52Z DEBUG Destroyed connection context.ldap2_139849980197240 2020-06-17T10:10:52Z DEBUG Created connection context.ldap2_139849980197240 2020-06-17T10:10:52Z DEBUG Parsing update file '/usr/share/ipa/updates/05-pre_upgrade_plugins.update' 2020-06-17T10:10:52Z DEBUG Executing upgrade plugin: update_managed_post_first 2020-06-17T10:10:52Z DEBUG raw: update_managed_post_first 2020-06-17T10:10:52Z DEBUG Executing upgrade plugin: update_replica_attribute_lists 2020-06-17T10:10:52Z DEBUG raw: update_replica_attribute_lists 2020-06-17T10:10:52Z DEBUG Start replication agreement exclude list update task 2020-06-17T10:10:52Z DEBUG Found 0 agreement(s) 2020-06-17T10:10:52Z DEBUG Done updating agreements 2020-06-17T10:10:52Z DEBUG Executing upgrade plugin: update_passync_privilege_check 2020-06-17T10:10:52Z DEBUG raw: update_passync_privilege_check 2020-06-17T10:10:52Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:10:52Z DEBUG Check if there is existing PassSync privilege 2020-06-17T10:10:52Z DEBUG PassSync privilege not found, this is a new update 2020-06-17T10:10:52Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:10:52Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:10:52Z DEBUG Executing upgrade plugin: update_referint 2020-06-17T10:10:52Z DEBUG raw: update_referint 2020-06-17T10:10:52Z DEBUG Upgrading referential integrity plugin configuration 2020-06-17T10:10:52Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:10:52Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:10:52Z DEBUG Initial value: LDAPEntry(ipapython.dn.DN('cn=referential integrity postoperation,cn=plugins,cn=config'), {'cn': [b'referential integrity postoperation'], 'nsslapd-plugin-depends-on-type': [b'database'], 'nsslapd-pluginDescription': [b'referential integrity plugin'], 'nsslapd-pluginEnabled': [b'on'], 'nsslapd-pluginId': [b'referint'], 'nsslapd-pluginInitfunc': [b'referint_postop_init'], 'nsslapd-pluginPath': [b'libreferint-plugin'], 'nsslapd-pluginType': [b'betxnpostoperation'], 'nsslapd-pluginVendor': [b'389 Project'], 'nsslapd-pluginVersion': [b'1.4.2.4'], 'nsslapd-pluginprecedence': [b'40'], 'objectClass': [b'top', b'nsSlapdPlugin', b'extensibleObject'], 'referint-logfile': [b'/var/log/dirsrv/slapd-LIN-TEST-LAN/referint'], 'referint-membership-attr': [b'member', b'uniquemember', b'owner', b'seeAlso'], 'referint-update-delay': [b'0']}) 2020-06-17T10:10:52Z DEBUG Plugin already uses new style, skipping 2020-06-17T10:10:52Z DEBUG Executing upgrade plugin: update_uniqueness_plugins_to_new_syntax 2020-06-17T10:10:52Z DEBUG raw: update_uniqueness_plugins_to_new_syntax 2020-06-17T10:10:52Z DEBUG No uniqueness plugin entries with old style configuration found 2020-06-17T10:10:52Z DEBUG LDAP update duration: /usr/share/ipa/updates/05-pre_upgrade_plugins.update 0.175 sec 2020-06-17T10:10:52Z DEBUG Parsing update file '/usr/share/ipa/updates/10-config.update' 2020-06-17T10:10:52Z DEBUG Updating existing entry: cn=config 2020-06-17T10:10:52Z DEBUG --------------------------------------------- 2020-06-17T10:10:52Z DEBUG Initial value 2020-06-17T10:10:52Z DEBUG dn: cn=config 2020-06-17T10:10:52Z DEBUG cn: 2020-06-17T10:10:52Z DEBUG config 2020-06-17T10:10:52Z DEBUG objectClass: 2020-06-17T10:10:52Z DEBUG top 2020-06-17T10:10:52Z DEBUG extensibleObject 2020-06-17T10:10:52Z DEBUG nsslapdConfig 2020-06-17T10:10:52Z DEBUG nsslapd-backendconfig: 2020-06-17T10:10:52Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG nsslapd-betype: 2020-06-17T10:10:52Z DEBUG ldbm database 2020-06-17T10:10:52Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:10:52Z DEBUG cn=schema 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG cn=monitor 2020-06-17T10:10:52Z DEBUG cn=config 2020-06-17T10:10:52Z DEBUG nsslapd-plugin: 2020-06-17T10:10:52Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-port 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:10:52Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:10:52Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:10:52Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:10:52Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:10:52Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:10:52Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:10:52Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:10:52Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:10:52Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:10:52Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:10:52Z DEBUG 600 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:10:52Z DEBUG 1 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:10:52Z DEBUG 600 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:10:52Z DEBUG 10 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:10:52Z DEBUG 16384 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:10:52Z DEBUG 600 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:10:52Z DEBUG 1 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-port: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-workingdir: 2020-06-17T10:10:52Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:52Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:10:52Z DEBUG 5 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:10:52Z DEBUG 1 2020-06-17T10:10:52Z DEBUG nsslapd-localuser: 2020-06-17T10:10:52Z DEBUG dirsrv 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:10:52Z DEBUG 1 2020-06-17T10:10:52Z DEBUG passwordInHistory: 2020-06-17T10:10:52Z DEBUG 6 2020-06-17T10:10:52Z DEBUG passwordUnlock: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG passwordGraceLimit: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:10:52Z DEBUG 1 2020-06-17T10:10:52Z DEBUG passwordMustChange: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:10:52Z DEBUG 100 2020-06-17T10:10:52Z DEBUG nsslapd-sizelimit: 2020-06-17T10:10:52Z DEBUG 2000 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:10:52Z DEBUG 100 2020-06-17T10:10:52Z DEBUG passwordWarning: 2020-06-17T10:10:52Z DEBUG 86400 2020-06-17T10:10:52Z DEBUG nsslapd-readonly: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-threadnumber: 2020-06-17T10:10:52Z DEBUG 16 2020-06-17T10:10:52Z DEBUG passwordLockout: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-localhost: 2020-06-17T10:10:52Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:10:52Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:10:52Z DEBUG 10000 2020-06-17T10:10:52Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:10:52Z DEBUG 40 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:10:52Z DEBUG 100 2020-06-17T10:10:52Z DEBUG passwordMinLength: 2020-06-17T10:10:52Z DEBUG 8 2020-06-17T10:10:52Z DEBUG passwordMinDigits: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG passwordMinAlphas: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG passwordMinUppers: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG passwordMinLowers: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG passwordMinSpecials: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG passwordMin8bit: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG passwordMaxRepeats: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG passwordMinCategories: 2020-06-17T10:10:52Z DEBUG 3 2020-06-17T10:10:52Z DEBUG passwordMinTokenLength: 2020-06-17T10:10:52Z DEBUG 3 2020-06-17T10:10:52Z DEBUG passwordPalindrome: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG passwordDictCheck: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG passwordDictPath: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG passwordUserAttributes: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG passwordBadWords: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG passwordMaxSequence: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG passwordMaxSeqSets: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG passwordMaxClassChars: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog: 2020-06-17T10:10:52Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:10:52Z DEBUG 1 2020-06-17T10:10:52Z DEBUG nsslapd-schemacheck: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-schemamod: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-schemareplace: 2020-06-17T10:10:52Z DEBUG replication-only 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:10:52Z DEBUG 500 2020-06-17T10:10:52Z DEBUG passwordMaxFailure: 2020-06-17T10:10:52Z DEBUG 3 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog: 2020-06-17T10:10:52Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:10:52Z DEBUG nsslapd-lastmod: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-security: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG passwordMaxAge: 2020-06-17T10:10:52Z DEBUG 8640000 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:10:52Z DEBUG week 2020-06-17T10:10:52Z DEBUG passwordResetFailureCount: 2020-06-17T10:10:52Z DEBUG 600 2020-06-17T10:10:52Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG passwordLegacyPolicy: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:10:52Z DEBUG 2 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:10:52Z DEBUG month 2020-06-17T10:10:52Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:10:52Z DEBUG month 2020-06-17T10:10:52Z DEBUG nsslapd-rootpw: 2020-06-17T10:10:52Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:10:52Z DEBUG passwordChange: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:10:52Z DEBUG 256 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:10:52Z DEBUG week 2020-06-17T10:10:52Z DEBUG nsslapd-securePort: 2020-06-17T10:10:52Z DEBUG 636 2020-06-17T10:10:52Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-timelimit: 2020-06-17T10:10:52Z DEBUG 3600 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:10:52Z DEBUG 100 2020-06-17T10:10:52Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:10:52Z DEBUG 64 2020-06-17T10:10:52Z DEBUG nsslapd-svrtab: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG passwordExp: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG passwordSendExpiringTime: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:10:52Z DEBUG day 2020-06-17T10:10:52Z DEBUG passwordLockoutDuration: 2020-06-17T10:10:52Z DEBUG 3600 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:10:52Z DEBUG 100 2020-06-17T10:10:52Z DEBUG nsslapd-idletimeout: 2020-06-17T10:10:52Z DEBUG 3600 2020-06-17T10:10:52Z DEBUG nsslapd-nagle: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:10:52Z DEBUG 5 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-csnlogging: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:10:52Z DEBUG month 2020-06-17T10:10:52Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG passwordCheckSyntax: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-listenhost: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-snmp-index: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:10:52Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:10:52Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:10:52Z DEBUG cn=Directory Manager 2020-06-17T10:10:52Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:10:52Z DEBUG uidNumber 2020-06-17T10:10:52Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:10:52Z DEBUG gidNumber 2020-06-17T10:10:52Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:10:52Z DEBUG dc=example,dc=com 2020-06-17T10:10:52Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-counters: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:10:52Z DEBUG 5 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:10:52Z DEBUG 2 2020-06-17T10:10:52Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:10:52Z DEBUG 5 2020-06-17T10:10:52Z DEBUG nsslapd-rootdn: 2020-06-17T10:10:52Z DEBUG cn=Directory Manager 2020-06-17T10:10:52Z DEBUG passwordMinAge: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog: 2020-06-17T10:10:52Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:52Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-result-tweak: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-maxbersize: 2020-06-17T10:10:52Z DEBUG 209715200 2020-06-17T10:10:52Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:10:52Z DEBUG 2097152 2020-06-17T10:10:52Z DEBUG nsslapd-versionstring: 2020-06-17T10:10:52Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:10:52Z DEBUG nsslapd-referralmode: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:10:52Z DEBUG 262144 2020-06-17T10:10:52Z DEBUG nsslapd-conntablesize: 2020-06-17T10:10:52Z DEBUG 1024 2020-06-17T10:10:52Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:10:52Z DEBUG allowed 2020-06-17T10:10:52Z DEBUG nsslapd-config: 2020-06-17T10:10:52Z DEBUG cn=config 2020-06-17T10:10:52Z DEBUG nsslapd-instancedir: 2020-06-17T10:10:52Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:52Z DEBUG nsslapd-schemadir: 2020-06-17T10:10:52Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:10:52Z DEBUG nsslapd-lockdir: 2020-06-17T10:10:52Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:52Z DEBUG nsslapd-tmpdir: 2020-06-17T10:10:52Z DEBUG /tmp 2020-06-17T10:10:52Z DEBUG nsslapd-certdir: 2020-06-17T10:10:52Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:52Z DEBUG nsslapd-ldifdir: 2020-06-17T10:10:52Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:10:52Z DEBUG nsslapd-bakdir: 2020-06-17T10:10:52Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:10:52Z DEBUG nsslapd-saslpath: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-rundir: 2020-06-17T10:10:52Z DEBUG /var/run/dirsrv 2020-06-17T10:10:52Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:10:52Z DEBUG 300000 2020-06-17T10:10:52Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-localssf: 2020-06-17T10:10:52Z DEBUG 71 2020-06-17T10:10:52Z DEBUG nsslapd-minssf: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:10:52Z DEBUG next 2020-06-17T10:10:52Z DEBUG nsslapd-validate-cert: 2020-06-17T10:10:52Z DEBUG warn 2020-06-17T10:10:52Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:10:52Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:52Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:10:52Z DEBUG 2097152 2020-06-17T10:10:52Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:10:52Z DEBUG 60 2020-06-17T10:10:52Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:10:52Z DEBUG 20971520 2020-06-17T10:10:52Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:10:52Z DEBUG nolog 2020-06-17T10:10:52Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:10:52Z DEBUG 2097152 2020-06-17T10:10:52Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:10:52Z DEBUG 1 2020-06-17T10:10:52Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:10:52Z DEBUG 128 2020-06-17T10:10:52Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:10:52Z DEBUG -10 2020-06-17T10:10:52Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:10:52Z DEBUG -10 2020-06-17T10:10:52Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:10:52Z DEBUG -10 2020-06-17T10:10:52Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:10:52Z DEBUG -1 2020-06-17T10:10:52Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:10:52Z DEBUG 600 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:10:52Z DEBUG 1 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:10:52Z DEBUG 100 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:10:52Z DEBUG 100 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:10:52Z DEBUG 1 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:10:52Z DEBUG 2 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:10:52Z DEBUG month 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:10:52Z DEBUG 5 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:10:52Z DEBUG week 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:10:52Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:52Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-logging-backend: 2020-06-17T10:10:52Z DEBUG dirsrv-log 2020-06-17T10:10:52Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:10:52Z DEBUG none 2020-06-17T10:10:52Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:10:52Z DEBUG warn-invalid 2020-06-17T10:10:52Z DEBUG passwordStorageScheme: 2020-06-17T10:10:52Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:52Z DEBUG passwordAdminDN: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:10:52Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-hash-filters: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG aci: 2020-06-17T10:10:52Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:52Z DEBUG only: set nsslapd-ssl-check-hostname to 'on', current value ['on'] 2020-06-17T10:10:52Z DEBUG only: updated value ['on'] 2020-06-17T10:10:52Z DEBUG --------------------------------------------- 2020-06-17T10:10:52Z DEBUG Final value after applying updates 2020-06-17T10:10:52Z DEBUG dn: cn=config 2020-06-17T10:10:52Z DEBUG cn: 2020-06-17T10:10:52Z DEBUG config 2020-06-17T10:10:52Z DEBUG objectClass: 2020-06-17T10:10:52Z DEBUG top 2020-06-17T10:10:52Z DEBUG extensibleObject 2020-06-17T10:10:52Z DEBUG nsslapdConfig 2020-06-17T10:10:52Z DEBUG nsslapd-backendconfig: 2020-06-17T10:10:52Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG nsslapd-betype: 2020-06-17T10:10:52Z DEBUG ldbm database 2020-06-17T10:10:52Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:10:52Z DEBUG cn=schema 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG cn=monitor 2020-06-17T10:10:52Z DEBUG cn=config 2020-06-17T10:10:52Z DEBUG nsslapd-plugin: 2020-06-17T10:10:52Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-port 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:10:52Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:10:52Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:10:52Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:10:52Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:10:52Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:10:52Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:10:52Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:10:52Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:10:52Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:10:52Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:10:52Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:10:52Z DEBUG 600 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:10:52Z DEBUG 1 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:10:52Z DEBUG 600 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:10:52Z DEBUG 10 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:10:52Z DEBUG 16384 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:10:52Z DEBUG 600 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:10:52Z DEBUG 1 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-port: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-workingdir: 2020-06-17T10:10:52Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:52Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:10:52Z DEBUG 5 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:10:52Z DEBUG 1 2020-06-17T10:10:52Z DEBUG nsslapd-localuser: 2020-06-17T10:10:52Z DEBUG dirsrv 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:10:52Z DEBUG 1 2020-06-17T10:10:52Z DEBUG passwordInHistory: 2020-06-17T10:10:52Z DEBUG 6 2020-06-17T10:10:52Z DEBUG passwordUnlock: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG passwordGraceLimit: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:10:52Z DEBUG 1 2020-06-17T10:10:52Z DEBUG passwordMustChange: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:10:52Z DEBUG 100 2020-06-17T10:10:52Z DEBUG nsslapd-sizelimit: 2020-06-17T10:10:52Z DEBUG 2000 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:10:52Z DEBUG 100 2020-06-17T10:10:52Z DEBUG passwordWarning: 2020-06-17T10:10:52Z DEBUG 86400 2020-06-17T10:10:52Z DEBUG nsslapd-readonly: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-threadnumber: 2020-06-17T10:10:52Z DEBUG 16 2020-06-17T10:10:52Z DEBUG passwordLockout: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-localhost: 2020-06-17T10:10:52Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:10:52Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:10:52Z DEBUG 10000 2020-06-17T10:10:52Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:10:52Z DEBUG 40 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:10:52Z DEBUG 100 2020-06-17T10:10:52Z DEBUG passwordMinLength: 2020-06-17T10:10:52Z DEBUG 8 2020-06-17T10:10:52Z DEBUG passwordMinDigits: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG passwordMinAlphas: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG passwordMinUppers: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG passwordMinLowers: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG passwordMinSpecials: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG passwordMin8bit: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG passwordMaxRepeats: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG passwordMinCategories: 2020-06-17T10:10:52Z DEBUG 3 2020-06-17T10:10:52Z DEBUG passwordMinTokenLength: 2020-06-17T10:10:52Z DEBUG 3 2020-06-17T10:10:52Z DEBUG passwordPalindrome: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG passwordDictCheck: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG passwordDictPath: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG passwordUserAttributes: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG passwordBadWords: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG passwordMaxSequence: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG passwordMaxSeqSets: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG passwordMaxClassChars: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog: 2020-06-17T10:10:52Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:10:52Z DEBUG 1 2020-06-17T10:10:52Z DEBUG nsslapd-schemacheck: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-schemamod: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-schemareplace: 2020-06-17T10:10:52Z DEBUG replication-only 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:10:52Z DEBUG 500 2020-06-17T10:10:52Z DEBUG passwordMaxFailure: 2020-06-17T10:10:52Z DEBUG 3 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog: 2020-06-17T10:10:52Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:10:52Z DEBUG nsslapd-lastmod: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-security: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG passwordMaxAge: 2020-06-17T10:10:52Z DEBUG 8640000 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:10:52Z DEBUG week 2020-06-17T10:10:52Z DEBUG passwordResetFailureCount: 2020-06-17T10:10:52Z DEBUG 600 2020-06-17T10:10:52Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG passwordLegacyPolicy: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:10:52Z DEBUG 2 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:10:52Z DEBUG month 2020-06-17T10:10:52Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:10:52Z DEBUG month 2020-06-17T10:10:52Z DEBUG nsslapd-rootpw: 2020-06-17T10:10:52Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:10:52Z DEBUG passwordChange: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:10:52Z DEBUG 256 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:10:52Z DEBUG week 2020-06-17T10:10:52Z DEBUG nsslapd-securePort: 2020-06-17T10:10:52Z DEBUG 636 2020-06-17T10:10:52Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-timelimit: 2020-06-17T10:10:52Z DEBUG 3600 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:10:52Z DEBUG 100 2020-06-17T10:10:52Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:10:52Z DEBUG 64 2020-06-17T10:10:52Z DEBUG nsslapd-svrtab: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG passwordExp: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG passwordSendExpiringTime: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:10:52Z DEBUG day 2020-06-17T10:10:52Z DEBUG passwordLockoutDuration: 2020-06-17T10:10:52Z DEBUG 3600 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:10:52Z DEBUG 100 2020-06-17T10:10:52Z DEBUG nsslapd-idletimeout: 2020-06-17T10:10:52Z DEBUG 3600 2020-06-17T10:10:52Z DEBUG nsslapd-nagle: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:10:52Z DEBUG 5 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-csnlogging: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:10:52Z DEBUG month 2020-06-17T10:10:52Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG passwordCheckSyntax: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-listenhost: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-snmp-index: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:10:52Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:10:52Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:10:52Z DEBUG cn=Directory Manager 2020-06-17T10:10:52Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:10:52Z DEBUG uidNumber 2020-06-17T10:10:52Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:10:52Z DEBUG gidNumber 2020-06-17T10:10:52Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:10:52Z DEBUG dc=example,dc=com 2020-06-17T10:10:52Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-counters: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:10:52Z DEBUG 5 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:10:52Z DEBUG 2 2020-06-17T10:10:52Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:10:52Z DEBUG 5 2020-06-17T10:10:52Z DEBUG nsslapd-rootdn: 2020-06-17T10:10:52Z DEBUG cn=Directory Manager 2020-06-17T10:10:52Z DEBUG passwordMinAge: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog: 2020-06-17T10:10:52Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:52Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-result-tweak: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-maxbersize: 2020-06-17T10:10:52Z DEBUG 209715200 2020-06-17T10:10:52Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:10:52Z DEBUG 2097152 2020-06-17T10:10:52Z DEBUG nsslapd-versionstring: 2020-06-17T10:10:52Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:10:52Z DEBUG nsslapd-referralmode: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:10:52Z DEBUG 262144 2020-06-17T10:10:52Z DEBUG nsslapd-conntablesize: 2020-06-17T10:10:52Z DEBUG 1024 2020-06-17T10:10:52Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:10:52Z DEBUG allowed 2020-06-17T10:10:52Z DEBUG nsslapd-config: 2020-06-17T10:10:52Z DEBUG cn=config 2020-06-17T10:10:52Z DEBUG nsslapd-instancedir: 2020-06-17T10:10:52Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:52Z DEBUG nsslapd-schemadir: 2020-06-17T10:10:52Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:10:52Z DEBUG nsslapd-lockdir: 2020-06-17T10:10:52Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:52Z DEBUG nsslapd-tmpdir: 2020-06-17T10:10:52Z DEBUG /tmp 2020-06-17T10:10:52Z DEBUG nsslapd-certdir: 2020-06-17T10:10:52Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:52Z DEBUG nsslapd-ldifdir: 2020-06-17T10:10:52Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:10:52Z DEBUG nsslapd-bakdir: 2020-06-17T10:10:52Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:10:52Z DEBUG nsslapd-saslpath: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-rundir: 2020-06-17T10:10:52Z DEBUG /var/run/dirsrv 2020-06-17T10:10:52Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:10:52Z DEBUG 300000 2020-06-17T10:10:52Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-localssf: 2020-06-17T10:10:52Z DEBUG 71 2020-06-17T10:10:52Z DEBUG nsslapd-minssf: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:10:52Z DEBUG next 2020-06-17T10:10:52Z DEBUG nsslapd-validate-cert: 2020-06-17T10:10:52Z DEBUG warn 2020-06-17T10:10:52Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:10:52Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:52Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:10:52Z DEBUG 2097152 2020-06-17T10:10:52Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:10:52Z DEBUG 60 2020-06-17T10:10:52Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:10:52Z DEBUG 20971520 2020-06-17T10:10:52Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:10:52Z DEBUG nolog 2020-06-17T10:10:52Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:10:52Z DEBUG 2097152 2020-06-17T10:10:52Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:10:52Z DEBUG 1 2020-06-17T10:10:52Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:10:52Z DEBUG 128 2020-06-17T10:10:52Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:10:52Z DEBUG -10 2020-06-17T10:10:52Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:10:52Z DEBUG -10 2020-06-17T10:10:52Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:10:52Z DEBUG -10 2020-06-17T10:10:52Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:10:52Z DEBUG -1 2020-06-17T10:10:52Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:10:52Z DEBUG 600 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:10:52Z DEBUG 0 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:10:52Z DEBUG 1 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:10:52Z DEBUG 100 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:10:52Z DEBUG 100 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:10:52Z DEBUG 1 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:10:52Z DEBUG 2 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:10:52Z DEBUG month 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:10:52Z DEBUG 5 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:10:52Z DEBUG week 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:10:52Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:52Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-logging-backend: 2020-06-17T10:10:52Z DEBUG dirsrv-log 2020-06-17T10:10:52Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:10:52Z DEBUG none 2020-06-17T10:10:52Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:10:52Z DEBUG warn-invalid 2020-06-17T10:10:52Z DEBUG passwordStorageScheme: 2020-06-17T10:10:52Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:52Z DEBUG passwordAdminDN: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:10:52Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:52Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-hash-filters: 2020-06-17T10:10:52Z DEBUG off 2020-06-17T10:10:52Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:10:52Z DEBUG 2020-06-17T10:10:52Z DEBUG aci: 2020-06-17T10:10:52Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:52Z DEBUG [] 2020-06-17T10:10:52Z DEBUG Updated 0 2020-06-17T10:10:52Z DEBUG Done 2020-06-17T10:10:52Z DEBUG Updating existing entry: cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG --------------------------------------------- 2020-06-17T10:10:52Z DEBUG Initial value 2020-06-17T10:10:52Z DEBUG dn: cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn: 2020-06-17T10:10:52Z DEBUG Kerberos Principal Name 2020-06-17T10:10:52Z DEBUG ipamodrdnfilter: 2020-06-17T10:10:52Z DEBUG (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) 2020-06-17T10:10:52Z DEBUG ipamodrdnscope: 2020-06-17T10:10:52Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:52Z DEBUG ipamodrdnsourceattr: 2020-06-17T10:10:52Z DEBUG uid 2020-06-17T10:10:52Z DEBUG ipamodrdnsuffix: 2020-06-17T10:10:52Z DEBUG @LIN.TEST.LAN 2020-06-17T10:10:52Z DEBUG ipamodrdntargetattr: 2020-06-17T10:10:52Z DEBUG krbPrincipalName 2020-06-17T10:10:52Z DEBUG objectClass: 2020-06-17T10:10:52Z DEBUG top 2020-06-17T10:10:52Z DEBUG extensibleObject 2020-06-17T10:10:52Z DEBUG remove: '60' from nsslapd-pluginPrecedence, current value [] 2020-06-17T10:10:52Z DEBUG remove: '60' not in nsslapd-pluginPrecedence 2020-06-17T10:10:52Z DEBUG --------------------------------------------- 2020-06-17T10:10:52Z DEBUG Final value after applying updates 2020-06-17T10:10:52Z DEBUG dn: cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn: 2020-06-17T10:10:52Z DEBUG Kerberos Principal Name 2020-06-17T10:10:52Z DEBUG ipamodrdnfilter: 2020-06-17T10:10:52Z DEBUG (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) 2020-06-17T10:10:52Z DEBUG ipamodrdnscope: 2020-06-17T10:10:52Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:52Z DEBUG ipamodrdnsourceattr: 2020-06-17T10:10:52Z DEBUG uid 2020-06-17T10:10:52Z DEBUG ipamodrdnsuffix: 2020-06-17T10:10:52Z DEBUG @LIN.TEST.LAN 2020-06-17T10:10:52Z DEBUG ipamodrdntargetattr: 2020-06-17T10:10:52Z DEBUG krbPrincipalName 2020-06-17T10:10:52Z DEBUG objectClass: 2020-06-17T10:10:52Z DEBUG top 2020-06-17T10:10:52Z DEBUG extensibleObject 2020-06-17T10:10:52Z DEBUG [] 2020-06-17T10:10:52Z DEBUG Updated 0 2020-06-17T10:10:52Z DEBUG Done 2020-06-17T10:10:52Z DEBUG Updating existing entry: cn=IPA MODRDN,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG --------------------------------------------- 2020-06-17T10:10:52Z DEBUG Initial value 2020-06-17T10:10:52Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn: 2020-06-17T10:10:52Z DEBUG IPA MODRDN 2020-06-17T10:10:52Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:52Z DEBUG database 2020-06-17T10:10:52Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:52Z DEBUG IPA MODRDN plugin 2020-06-17T10:10:52Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:52Z DEBUG IPA MODRDN 2020-06-17T10:10:52Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:52Z DEBUG ipamodrdn_init 2020-06-17T10:10:52Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:52Z DEBUG libipa_modrdn 2020-06-17T10:10:52Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:52Z DEBUG betxnpostoperation 2020-06-17T10:10:52Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:52Z DEBUG Red Hat, Inc. 2020-06-17T10:10:52Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:52Z DEBUG 1.0 2020-06-17T10:10:52Z DEBUG nsslapd-pluginprecedence: 2020-06-17T10:10:52Z DEBUG 60 2020-06-17T10:10:52Z DEBUG objectClass: 2020-06-17T10:10:52Z DEBUG top 2020-06-17T10:10:52Z DEBUG nsSlapdPlugin 2020-06-17T10:10:52Z DEBUG extensibleObject 2020-06-17T10:10:52Z DEBUG only: set nsslapd-pluginPrecedence to '60', current value ['60'] 2020-06-17T10:10:52Z DEBUG only: updated value ['60'] 2020-06-17T10:10:52Z DEBUG --------------------------------------------- 2020-06-17T10:10:52Z DEBUG Final value after applying updates 2020-06-17T10:10:52Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2020-06-17T10:10:52Z DEBUG cn: 2020-06-17T10:10:52Z DEBUG IPA MODRDN 2020-06-17T10:10:52Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:52Z DEBUG database 2020-06-17T10:10:52Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:52Z DEBUG IPA MODRDN plugin 2020-06-17T10:10:52Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:52Z DEBUG on 2020-06-17T10:10:52Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:52Z DEBUG IPA MODRDN 2020-06-17T10:10:52Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:52Z DEBUG ipamodrdn_init 2020-06-17T10:10:52Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:52Z DEBUG libipa_modrdn 2020-06-17T10:10:52Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:52Z DEBUG betxnpostoperation 2020-06-17T10:10:52Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:52Z DEBUG Red Hat, Inc. 2020-06-17T10:10:52Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:52Z DEBUG 1.0 2020-06-17T10:10:52Z DEBUG nsslapd-pluginprecedence: 2020-06-17T10:10:52Z DEBUG 60 2020-06-17T10:10:52Z DEBUG objectClass: 2020-06-17T10:10:52Z DEBUG top 2020-06-17T10:10:52Z DEBUG nsSlapdPlugin 2020-06-17T10:10:52Z DEBUG extensibleObject 2020-06-17T10:10:52Z DEBUG [] 2020-06-17T10:10:52Z DEBUG Updated 0 2020-06-17T10:10:52Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsslapdConfig 2020-06-17T10:10:53Z DEBUG nsslapd-backendconfig: 2020-06-17T10:10:53Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-betype: 2020-06-17T10:10:53Z DEBUG ldbm database 2020-06-17T10:10:53Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:10:53Z DEBUG cn=schema 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG cn=monitor 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-plugin: 2020-06-17T10:10:53Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-port 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 10 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:10:53Z DEBUG 16384 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-port: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-workingdir: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-localuser: 2020-06-17T10:10:53Z DEBUG dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordInHistory: 2020-06-17T10:10:53Z DEBUG 6 2020-06-17T10:10:53Z DEBUG passwordUnlock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordGraceLimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordMustChange: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-sizelimit: 2020-06-17T10:10:53Z DEBUG 2000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordWarning: 2020-06-17T10:10:53Z DEBUG 86400 2020-06-17T10:10:53Z DEBUG nsslapd-readonly: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-threadnumber: 2020-06-17T10:10:53Z DEBUG 16 2020-06-17T10:10:53Z DEBUG passwordLockout: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-localhost: 2020-06-17T10:10:53Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:10:53Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:10:53Z DEBUG 10000 2020-06-17T10:10:53Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:10:53Z DEBUG 40 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordMinLength: 2020-06-17T10:10:53Z DEBUG 8 2020-06-17T10:10:53Z DEBUG passwordMinDigits: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinAlphas: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinUppers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinLowers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinSpecials: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMin8bit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxRepeats: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinCategories: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordMinTokenLength: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordPalindrome: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictCheck: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictPath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordUserAttributes: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordBadWords: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordMaxSequence: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxSeqSets: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxClassChars: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-schemacheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-schemamod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schemareplace: 2020-06-17T10:10:53Z DEBUG replication-only 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 500 2020-06-17T10:10:53Z DEBUG passwordMaxFailure: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:10:53Z DEBUG nsslapd-lastmod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-security: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordMaxAge: 2020-06-17T10:10:53Z DEBUG 8640000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG passwordResetFailureCount: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordLegacyPolicy: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-rootpw: 2020-06-17T10:10:53Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:10:53Z DEBUG passwordChange: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:10:53Z DEBUG 256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-securePort: 2020-06-17T10:10:53Z DEBUG 636 2020-06-17T10:10:53Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-timelimit: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:10:53Z DEBUG 64 2020-06-17T10:10:53Z DEBUG nsslapd-svrtab: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordExp: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordSendExpiringTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG day 2020-06-17T10:10:53Z DEBUG passwordLockoutDuration: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-idletimeout: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-nagle: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-csnlogging: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordCheckSyntax: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-snmp-index: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:10:53Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:10:53Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:10:53Z DEBUG uidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:10:53Z DEBUG gidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:10:53Z DEBUG dc=example,dc=com 2020-06-17T10:10:53Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-counters: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-rootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG passwordMinAge: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-result-tweak: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-maxbersize: 2020-06-17T10:10:53Z DEBUG 209715200 2020-06-17T10:10:53Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-versionstring: 2020-06-17T10:10:53Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-referralmode: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:10:53Z DEBUG 262144 2020-06-17T10:10:53Z DEBUG nsslapd-conntablesize: 2020-06-17T10:10:53Z DEBUG 1024 2020-06-17T10:10:53Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:10:53Z DEBUG allowed 2020-06-17T10:10:53Z DEBUG nsslapd-config: 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-instancedir: 2020-06-17T10:10:53Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-schemadir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:10:53Z DEBUG nsslapd-lockdir: 2020-06-17T10:10:53Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-tmpdir: 2020-06-17T10:10:53Z DEBUG /tmp 2020-06-17T10:10:53Z DEBUG nsslapd-certdir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-ldifdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:10:53Z DEBUG nsslapd-bakdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:10:53Z DEBUG nsslapd-saslpath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rundir: 2020-06-17T10:10:53Z DEBUG /var/run/dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:10:53Z DEBUG 300000 2020-06-17T10:10:53Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-localssf: 2020-06-17T10:10:53Z DEBUG 71 2020-06-17T10:10:53Z DEBUG nsslapd-minssf: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:10:53Z DEBUG next 2020-06-17T10:10:53Z DEBUG nsslapd-validate-cert: 2020-06-17T10:10:53Z DEBUG warn 2020-06-17T10:10:53Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:10:53Z DEBUG 60 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:10:53Z DEBUG 20971520 2020-06-17T10:10:53Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:10:53Z DEBUG nolog 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:10:53Z DEBUG 128 2020-06-17T10:10:53Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:10:53Z DEBUG -1 2020-06-17T10:10:53Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-logging-backend: 2020-06-17T10:10:53Z DEBUG dirsrv-log 2020-06-17T10:10:53Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:10:53Z DEBUG warn-invalid 2020-06-17T10:10:53Z DEBUG passwordStorageScheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG passwordAdminDN: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-hash-filters: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsslapdConfig 2020-06-17T10:10:53Z DEBUG nsslapd-backendconfig: 2020-06-17T10:10:53Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-betype: 2020-06-17T10:10:53Z DEBUG ldbm database 2020-06-17T10:10:53Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:10:53Z DEBUG cn=schema 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG cn=monitor 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-plugin: 2020-06-17T10:10:53Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-port 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 10 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:10:53Z DEBUG 16384 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-port: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-workingdir: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-localuser: 2020-06-17T10:10:53Z DEBUG dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordInHistory: 2020-06-17T10:10:53Z DEBUG 6 2020-06-17T10:10:53Z DEBUG passwordUnlock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordGraceLimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordMustChange: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-sizelimit: 2020-06-17T10:10:53Z DEBUG 2000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordWarning: 2020-06-17T10:10:53Z DEBUG 86400 2020-06-17T10:10:53Z DEBUG nsslapd-readonly: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-threadnumber: 2020-06-17T10:10:53Z DEBUG 16 2020-06-17T10:10:53Z DEBUG passwordLockout: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-localhost: 2020-06-17T10:10:53Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:10:53Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:10:53Z DEBUG 10000 2020-06-17T10:10:53Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:10:53Z DEBUG 40 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordMinLength: 2020-06-17T10:10:53Z DEBUG 8 2020-06-17T10:10:53Z DEBUG passwordMinDigits: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinAlphas: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinUppers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinLowers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinSpecials: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMin8bit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxRepeats: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinCategories: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordMinTokenLength: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordPalindrome: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictCheck: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictPath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordUserAttributes: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordBadWords: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordMaxSequence: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxSeqSets: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxClassChars: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-schemacheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-schemamod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schemareplace: 2020-06-17T10:10:53Z DEBUG replication-only 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 500 2020-06-17T10:10:53Z DEBUG passwordMaxFailure: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:10:53Z DEBUG nsslapd-lastmod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-security: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordMaxAge: 2020-06-17T10:10:53Z DEBUG 8640000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG passwordResetFailureCount: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordLegacyPolicy: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-rootpw: 2020-06-17T10:10:53Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:10:53Z DEBUG passwordChange: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:10:53Z DEBUG 256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-securePort: 2020-06-17T10:10:53Z DEBUG 636 2020-06-17T10:10:53Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-timelimit: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:10:53Z DEBUG 64 2020-06-17T10:10:53Z DEBUG nsslapd-svrtab: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordExp: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordSendExpiringTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG day 2020-06-17T10:10:53Z DEBUG passwordLockoutDuration: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-idletimeout: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-nagle: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-csnlogging: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordCheckSyntax: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-snmp-index: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:10:53Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:10:53Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:10:53Z DEBUG uidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:10:53Z DEBUG gidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:10:53Z DEBUG dc=example,dc=com 2020-06-17T10:10:53Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-counters: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-rootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG passwordMinAge: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-result-tweak: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-maxbersize: 2020-06-17T10:10:53Z DEBUG 209715200 2020-06-17T10:10:53Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-versionstring: 2020-06-17T10:10:53Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-referralmode: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:10:53Z DEBUG 262144 2020-06-17T10:10:53Z DEBUG nsslapd-conntablesize: 2020-06-17T10:10:53Z DEBUG 1024 2020-06-17T10:10:53Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:10:53Z DEBUG allowed 2020-06-17T10:10:53Z DEBUG nsslapd-config: 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-instancedir: 2020-06-17T10:10:53Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-schemadir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:10:53Z DEBUG nsslapd-lockdir: 2020-06-17T10:10:53Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-tmpdir: 2020-06-17T10:10:53Z DEBUG /tmp 2020-06-17T10:10:53Z DEBUG nsslapd-certdir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-ldifdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:10:53Z DEBUG nsslapd-bakdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:10:53Z DEBUG nsslapd-saslpath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rundir: 2020-06-17T10:10:53Z DEBUG /var/run/dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:10:53Z DEBUG 300000 2020-06-17T10:10:53Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-localssf: 2020-06-17T10:10:53Z DEBUG 71 2020-06-17T10:10:53Z DEBUG nsslapd-minssf: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:10:53Z DEBUG next 2020-06-17T10:10:53Z DEBUG nsslapd-validate-cert: 2020-06-17T10:10:53Z DEBUG warn 2020-06-17T10:10:53Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:10:53Z DEBUG 60 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:10:53Z DEBUG 20971520 2020-06-17T10:10:53Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:10:53Z DEBUG nolog 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:10:53Z DEBUG 128 2020-06-17T10:10:53Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:10:53Z DEBUG -1 2020-06-17T10:10:53Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-logging-backend: 2020-06-17T10:10:53Z DEBUG dirsrv-log 2020-06-17T10:10:53Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:10:53Z DEBUG warn-invalid 2020-06-17T10:10:53Z DEBUG passwordStorageScheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG passwordAdminDN: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-hash-filters: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=config,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=config,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG config 2020-06-17T10:10:53Z DEBUG nsslapd-db-locks: 2020-06-17T10:10:53Z DEBUG 50000 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsslapd-lookthroughlimit: 2020-06-17T10:10:53Z DEBUG 5000 2020-06-17T10:10:53Z DEBUG nsslapd-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-idlistscanlimit: 2020-06-17T10:10:53Z DEBUG 4000 2020-06-17T10:10:53Z DEBUG nsslapd-directory: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/db 2020-06-17T10:10:53Z DEBUG nsslapd-import-cachesize: 2020-06-17T10:10:53Z DEBUG 16777216 2020-06-17T10:10:53Z DEBUG nsslapd-idl-switch: 2020-06-17T10:10:53Z DEBUG new 2020-06-17T10:10:53Z DEBUG nsslapd-search-bypass-filter-test: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-search-use-vlv-index: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-exclude-from-export: 2020-06-17T10:10:53Z DEBUG entrydn entryid dncomp parentid numSubordinates tombstonenumsubordinates entryusn 2020-06-17T10:10:53Z DEBUG nsslapd-serial-lock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-subtree-rename-switch: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pagedlookthroughlimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-pagedidlistscanlimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-rangelookthroughlimit: 2020-06-17T10:10:53Z DEBUG 5000 2020-06-17T10:10:53Z DEBUG nsslapd-backend-opt-level: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-backend-implement: 2020-06-17T10:10:53Z DEBUG bdb 2020-06-17T10:10:53Z DEBUG replace: updated value ['100000'] 2020-06-17T10:10:53Z DEBUG replace: updated value ['100000'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=config,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG config 2020-06-17T10:10:53Z DEBUG nsslapd-db-locks: 2020-06-17T10:10:53Z DEBUG 50000 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsslapd-lookthroughlimit: 2020-06-17T10:10:53Z DEBUG 100000 2020-06-17T10:10:53Z DEBUG nsslapd-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-idlistscanlimit: 2020-06-17T10:10:53Z DEBUG 100000 2020-06-17T10:10:53Z DEBUG nsslapd-directory: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/db 2020-06-17T10:10:53Z DEBUG nsslapd-import-cachesize: 2020-06-17T10:10:53Z DEBUG 16777216 2020-06-17T10:10:53Z DEBUG nsslapd-idl-switch: 2020-06-17T10:10:53Z DEBUG new 2020-06-17T10:10:53Z DEBUG nsslapd-search-bypass-filter-test: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-search-use-vlv-index: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-exclude-from-export: 2020-06-17T10:10:53Z DEBUG entrydn entryid dncomp parentid numSubordinates tombstonenumsubordinates entryusn 2020-06-17T10:10:53Z DEBUG nsslapd-serial-lock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-subtree-rename-switch: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pagedlookthroughlimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-pagedidlistscanlimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-rangelookthroughlimit: 2020-06-17T10:10:53Z DEBUG 5000 2020-06-17T10:10:53Z DEBUG nsslapd-backend-opt-level: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-backend-implement: 2020-06-17T10:10:53Z DEBUG bdb 2020-06-17T10:10:53Z DEBUG [(2, 'nsslapd-lookthroughlimit', ['100000']), (2, 'nsslapd-idlistscanlimit', ['100000'])] 2020-06-17T10:10:53Z DEBUG Updated 1 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG New entry: cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectclass: 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG anonymous-limits 2020-06-17T10:10:53Z DEBUG nsSizeLimit: 2020-06-17T10:10:53Z DEBUG 5000 2020-06-17T10:10:53Z DEBUG nsLookThroughLimit: 2020-06-17T10:10:53Z DEBUG 5000 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectclass: 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG anonymous-limits 2020-06-17T10:10:53Z DEBUG nsSizeLimit: 2020-06-17T10:10:53Z DEBUG 5000 2020-06-17T10:10:53Z DEBUG nsLookThroughLimit: 2020-06-17T10:10:53Z DEBUG 5000 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsslapdConfig 2020-06-17T10:10:53Z DEBUG nsslapd-backendconfig: 2020-06-17T10:10:53Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-betype: 2020-06-17T10:10:53Z DEBUG ldbm database 2020-06-17T10:10:53Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:10:53Z DEBUG cn=schema 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG cn=monitor 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-plugin: 2020-06-17T10:10:53Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-port 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 10 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:10:53Z DEBUG 16384 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-port: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-workingdir: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-localuser: 2020-06-17T10:10:53Z DEBUG dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordInHistory: 2020-06-17T10:10:53Z DEBUG 6 2020-06-17T10:10:53Z DEBUG passwordUnlock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordGraceLimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordMustChange: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-sizelimit: 2020-06-17T10:10:53Z DEBUG 2000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordWarning: 2020-06-17T10:10:53Z DEBUG 86400 2020-06-17T10:10:53Z DEBUG nsslapd-readonly: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-threadnumber: 2020-06-17T10:10:53Z DEBUG 16 2020-06-17T10:10:53Z DEBUG passwordLockout: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-localhost: 2020-06-17T10:10:53Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:10:53Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:10:53Z DEBUG 10000 2020-06-17T10:10:53Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:10:53Z DEBUG 40 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordMinLength: 2020-06-17T10:10:53Z DEBUG 8 2020-06-17T10:10:53Z DEBUG passwordMinDigits: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinAlphas: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinUppers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinLowers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinSpecials: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMin8bit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxRepeats: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinCategories: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordMinTokenLength: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordPalindrome: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictCheck: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictPath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordUserAttributes: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordBadWords: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordMaxSequence: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxSeqSets: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxClassChars: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-schemacheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-schemamod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schemareplace: 2020-06-17T10:10:53Z DEBUG replication-only 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 500 2020-06-17T10:10:53Z DEBUG passwordMaxFailure: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:10:53Z DEBUG nsslapd-lastmod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-security: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordMaxAge: 2020-06-17T10:10:53Z DEBUG 8640000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG passwordResetFailureCount: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordLegacyPolicy: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-rootpw: 2020-06-17T10:10:53Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:10:53Z DEBUG passwordChange: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:10:53Z DEBUG 256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-securePort: 2020-06-17T10:10:53Z DEBUG 636 2020-06-17T10:10:53Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-timelimit: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:10:53Z DEBUG 64 2020-06-17T10:10:53Z DEBUG nsslapd-svrtab: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordExp: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordSendExpiringTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG day 2020-06-17T10:10:53Z DEBUG passwordLockoutDuration: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-idletimeout: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-nagle: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-csnlogging: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordCheckSyntax: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-snmp-index: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:10:53Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:10:53Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:10:53Z DEBUG uidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:10:53Z DEBUG gidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:10:53Z DEBUG dc=example,dc=com 2020-06-17T10:10:53Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-counters: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-rootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG passwordMinAge: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-result-tweak: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-maxbersize: 2020-06-17T10:10:53Z DEBUG 209715200 2020-06-17T10:10:53Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-versionstring: 2020-06-17T10:10:53Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-referralmode: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:10:53Z DEBUG 262144 2020-06-17T10:10:53Z DEBUG nsslapd-conntablesize: 2020-06-17T10:10:53Z DEBUG 1024 2020-06-17T10:10:53Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:10:53Z DEBUG allowed 2020-06-17T10:10:53Z DEBUG nsslapd-config: 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-instancedir: 2020-06-17T10:10:53Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-schemadir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:10:53Z DEBUG nsslapd-lockdir: 2020-06-17T10:10:53Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-tmpdir: 2020-06-17T10:10:53Z DEBUG /tmp 2020-06-17T10:10:53Z DEBUG nsslapd-certdir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-ldifdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:10:53Z DEBUG nsslapd-bakdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:10:53Z DEBUG nsslapd-saslpath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rundir: 2020-06-17T10:10:53Z DEBUG /var/run/dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:10:53Z DEBUG 300000 2020-06-17T10:10:53Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-localssf: 2020-06-17T10:10:53Z DEBUG 71 2020-06-17T10:10:53Z DEBUG nsslapd-minssf: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:10:53Z DEBUG next 2020-06-17T10:10:53Z DEBUG nsslapd-validate-cert: 2020-06-17T10:10:53Z DEBUG warn 2020-06-17T10:10:53Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:10:53Z DEBUG 60 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:10:53Z DEBUG 20971520 2020-06-17T10:10:53Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:10:53Z DEBUG nolog 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:10:53Z DEBUG 128 2020-06-17T10:10:53Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:10:53Z DEBUG -1 2020-06-17T10:10:53Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-logging-backend: 2020-06-17T10:10:53Z DEBUG dirsrv-log 2020-06-17T10:10:53Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:10:53Z DEBUG warn-invalid 2020-06-17T10:10:53Z DEBUG passwordStorageScheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG passwordAdminDN: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-hash-filters: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG only: set nsslapd-anonlimitsdn to 'cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan', current value [''] 2020-06-17T10:10:53Z DEBUG only: updated value ['cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsslapdConfig 2020-06-17T10:10:53Z DEBUG nsslapd-backendconfig: 2020-06-17T10:10:53Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-betype: 2020-06-17T10:10:53Z DEBUG ldbm database 2020-06-17T10:10:53Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:10:53Z DEBUG cn=schema 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG cn=monitor 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-plugin: 2020-06-17T10:10:53Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-port 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 10 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:10:53Z DEBUG 16384 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-port: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-workingdir: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-localuser: 2020-06-17T10:10:53Z DEBUG dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordInHistory: 2020-06-17T10:10:53Z DEBUG 6 2020-06-17T10:10:53Z DEBUG passwordUnlock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordGraceLimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordMustChange: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-sizelimit: 2020-06-17T10:10:53Z DEBUG 2000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordWarning: 2020-06-17T10:10:53Z DEBUG 86400 2020-06-17T10:10:53Z DEBUG nsslapd-readonly: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-threadnumber: 2020-06-17T10:10:53Z DEBUG 16 2020-06-17T10:10:53Z DEBUG passwordLockout: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-localhost: 2020-06-17T10:10:53Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:10:53Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:10:53Z DEBUG 10000 2020-06-17T10:10:53Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:10:53Z DEBUG 40 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordMinLength: 2020-06-17T10:10:53Z DEBUG 8 2020-06-17T10:10:53Z DEBUG passwordMinDigits: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinAlphas: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinUppers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinLowers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinSpecials: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMin8bit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxRepeats: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinCategories: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordMinTokenLength: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordPalindrome: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictCheck: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictPath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordUserAttributes: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordBadWords: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordMaxSequence: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxSeqSets: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxClassChars: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-schemacheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-schemamod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schemareplace: 2020-06-17T10:10:53Z DEBUG replication-only 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 500 2020-06-17T10:10:53Z DEBUG passwordMaxFailure: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:10:53Z DEBUG nsslapd-lastmod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-security: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordMaxAge: 2020-06-17T10:10:53Z DEBUG 8640000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG passwordResetFailureCount: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordLegacyPolicy: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-rootpw: 2020-06-17T10:10:53Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:10:53Z DEBUG passwordChange: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:10:53Z DEBUG 256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-securePort: 2020-06-17T10:10:53Z DEBUG 636 2020-06-17T10:10:53Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-timelimit: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:10:53Z DEBUG 64 2020-06-17T10:10:53Z DEBUG nsslapd-svrtab: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordExp: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordSendExpiringTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG day 2020-06-17T10:10:53Z DEBUG passwordLockoutDuration: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-idletimeout: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-nagle: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-csnlogging: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordCheckSyntax: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-snmp-index: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:10:53Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:10:53Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:10:53Z DEBUG uidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:10:53Z DEBUG gidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:10:53Z DEBUG dc=example,dc=com 2020-06-17T10:10:53Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:10:53Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-counters: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-rootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG passwordMinAge: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-result-tweak: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-maxbersize: 2020-06-17T10:10:53Z DEBUG 209715200 2020-06-17T10:10:53Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-versionstring: 2020-06-17T10:10:53Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-referralmode: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:10:53Z DEBUG 262144 2020-06-17T10:10:53Z DEBUG nsslapd-conntablesize: 2020-06-17T10:10:53Z DEBUG 1024 2020-06-17T10:10:53Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:10:53Z DEBUG allowed 2020-06-17T10:10:53Z DEBUG nsslapd-config: 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-instancedir: 2020-06-17T10:10:53Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-schemadir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:10:53Z DEBUG nsslapd-lockdir: 2020-06-17T10:10:53Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-tmpdir: 2020-06-17T10:10:53Z DEBUG /tmp 2020-06-17T10:10:53Z DEBUG nsslapd-certdir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-ldifdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:10:53Z DEBUG nsslapd-bakdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:10:53Z DEBUG nsslapd-saslpath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rundir: 2020-06-17T10:10:53Z DEBUG /var/run/dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:10:53Z DEBUG 300000 2020-06-17T10:10:53Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-localssf: 2020-06-17T10:10:53Z DEBUG 71 2020-06-17T10:10:53Z DEBUG nsslapd-minssf: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:10:53Z DEBUG next 2020-06-17T10:10:53Z DEBUG nsslapd-validate-cert: 2020-06-17T10:10:53Z DEBUG warn 2020-06-17T10:10:53Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:10:53Z DEBUG 60 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:10:53Z DEBUG 20971520 2020-06-17T10:10:53Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:10:53Z DEBUG nolog 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:10:53Z DEBUG 128 2020-06-17T10:10:53Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:10:53Z DEBUG -1 2020-06-17T10:10:53Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-logging-backend: 2020-06-17T10:10:53Z DEBUG dirsrv-log 2020-06-17T10:10:53Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:10:53Z DEBUG warn-invalid 2020-06-17T10:10:53Z DEBUG passwordStorageScheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG passwordAdminDN: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-hash-filters: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG [(2, 'nsslapd-anonlimitsdn', ['cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:10:53Z DEBUG Updated 1 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsslapdConfig 2020-06-17T10:10:53Z DEBUG nsslapd-backendconfig: 2020-06-17T10:10:53Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-betype: 2020-06-17T10:10:53Z DEBUG ldbm database 2020-06-17T10:10:53Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:10:53Z DEBUG cn=schema 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG cn=monitor 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-plugin: 2020-06-17T10:10:53Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-port 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 10 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:10:53Z DEBUG 16384 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-port: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-workingdir: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-localuser: 2020-06-17T10:10:53Z DEBUG dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordInHistory: 2020-06-17T10:10:53Z DEBUG 6 2020-06-17T10:10:53Z DEBUG passwordUnlock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordGraceLimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordMustChange: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-sizelimit: 2020-06-17T10:10:53Z DEBUG 2000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordWarning: 2020-06-17T10:10:53Z DEBUG 86400 2020-06-17T10:10:53Z DEBUG nsslapd-readonly: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-threadnumber: 2020-06-17T10:10:53Z DEBUG 16 2020-06-17T10:10:53Z DEBUG passwordLockout: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-localhost: 2020-06-17T10:10:53Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:10:53Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:10:53Z DEBUG 10000 2020-06-17T10:10:53Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:10:53Z DEBUG 40 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordMinLength: 2020-06-17T10:10:53Z DEBUG 8 2020-06-17T10:10:53Z DEBUG passwordMinDigits: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinAlphas: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinUppers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinLowers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinSpecials: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMin8bit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxRepeats: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinCategories: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordMinTokenLength: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordPalindrome: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictCheck: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictPath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordUserAttributes: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordBadWords: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordMaxSequence: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxSeqSets: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxClassChars: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-schemacheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-schemamod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schemareplace: 2020-06-17T10:10:53Z DEBUG replication-only 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 500 2020-06-17T10:10:53Z DEBUG passwordMaxFailure: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:10:53Z DEBUG nsslapd-lastmod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-security: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordMaxAge: 2020-06-17T10:10:53Z DEBUG 8640000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG passwordResetFailureCount: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordLegacyPolicy: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-rootpw: 2020-06-17T10:10:53Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:10:53Z DEBUG passwordChange: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:10:53Z DEBUG 256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-securePort: 2020-06-17T10:10:53Z DEBUG 636 2020-06-17T10:10:53Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-timelimit: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:10:53Z DEBUG 64 2020-06-17T10:10:53Z DEBUG nsslapd-svrtab: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordExp: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordSendExpiringTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG day 2020-06-17T10:10:53Z DEBUG passwordLockoutDuration: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-idletimeout: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-nagle: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-csnlogging: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordCheckSyntax: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-snmp-index: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:10:53Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:10:53Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:10:53Z DEBUG uidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:10:53Z DEBUG gidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:10:53Z DEBUG dc=example,dc=com 2020-06-17T10:10:53Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:10:53Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-counters: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-rootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG passwordMinAge: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-result-tweak: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-maxbersize: 2020-06-17T10:10:53Z DEBUG 209715200 2020-06-17T10:10:53Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-versionstring: 2020-06-17T10:10:53Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-referralmode: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:10:53Z DEBUG 262144 2020-06-17T10:10:53Z DEBUG nsslapd-conntablesize: 2020-06-17T10:10:53Z DEBUG 1024 2020-06-17T10:10:53Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:10:53Z DEBUG allowed 2020-06-17T10:10:53Z DEBUG nsslapd-config: 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-instancedir: 2020-06-17T10:10:53Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-schemadir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:10:53Z DEBUG nsslapd-lockdir: 2020-06-17T10:10:53Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-tmpdir: 2020-06-17T10:10:53Z DEBUG /tmp 2020-06-17T10:10:53Z DEBUG nsslapd-certdir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-ldifdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:10:53Z DEBUG nsslapd-bakdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:10:53Z DEBUG nsslapd-saslpath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rundir: 2020-06-17T10:10:53Z DEBUG /var/run/dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:10:53Z DEBUG 300000 2020-06-17T10:10:53Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-localssf: 2020-06-17T10:10:53Z DEBUG 71 2020-06-17T10:10:53Z DEBUG nsslapd-minssf: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:10:53Z DEBUG next 2020-06-17T10:10:53Z DEBUG nsslapd-validate-cert: 2020-06-17T10:10:53Z DEBUG warn 2020-06-17T10:10:53Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:10:53Z DEBUG 60 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:10:53Z DEBUG 20971520 2020-06-17T10:10:53Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:10:53Z DEBUG nolog 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:10:53Z DEBUG 128 2020-06-17T10:10:53Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:10:53Z DEBUG -1 2020-06-17T10:10:53Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-logging-backend: 2020-06-17T10:10:53Z DEBUG dirsrv-log 2020-06-17T10:10:53Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:10:53Z DEBUG warn-invalid 2020-06-17T10:10:53Z DEBUG passwordStorageScheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG passwordAdminDN: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-hash-filters: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG add: 'dc=lin,dc=test,dc=lan' to nsslapd-defaultNamingContext, current value ['dc=lin,dc=test,dc=lan'] 2020-06-17T10:10:53Z DEBUG add: updated value ['dc=lin,dc=test,dc=lan'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsslapdConfig 2020-06-17T10:10:53Z DEBUG nsslapd-backendconfig: 2020-06-17T10:10:53Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-betype: 2020-06-17T10:10:53Z DEBUG ldbm database 2020-06-17T10:10:53Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:10:53Z DEBUG cn=schema 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG cn=monitor 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-plugin: 2020-06-17T10:10:53Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-port 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 10 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:10:53Z DEBUG 16384 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-port: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-workingdir: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-localuser: 2020-06-17T10:10:53Z DEBUG dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordInHistory: 2020-06-17T10:10:53Z DEBUG 6 2020-06-17T10:10:53Z DEBUG passwordUnlock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordGraceLimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordMustChange: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-sizelimit: 2020-06-17T10:10:53Z DEBUG 2000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordWarning: 2020-06-17T10:10:53Z DEBUG 86400 2020-06-17T10:10:53Z DEBUG nsslapd-readonly: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-threadnumber: 2020-06-17T10:10:53Z DEBUG 16 2020-06-17T10:10:53Z DEBUG passwordLockout: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-localhost: 2020-06-17T10:10:53Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:10:53Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:10:53Z DEBUG 10000 2020-06-17T10:10:53Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:10:53Z DEBUG 40 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordMinLength: 2020-06-17T10:10:53Z DEBUG 8 2020-06-17T10:10:53Z DEBUG passwordMinDigits: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinAlphas: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinUppers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinLowers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinSpecials: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMin8bit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxRepeats: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinCategories: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordMinTokenLength: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordPalindrome: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictCheck: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictPath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordUserAttributes: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordBadWords: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordMaxSequence: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxSeqSets: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxClassChars: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-schemacheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-schemamod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schemareplace: 2020-06-17T10:10:53Z DEBUG replication-only 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 500 2020-06-17T10:10:53Z DEBUG passwordMaxFailure: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:10:53Z DEBUG nsslapd-lastmod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-security: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordMaxAge: 2020-06-17T10:10:53Z DEBUG 8640000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG passwordResetFailureCount: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordLegacyPolicy: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-rootpw: 2020-06-17T10:10:53Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:10:53Z DEBUG passwordChange: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:10:53Z DEBUG 256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-securePort: 2020-06-17T10:10:53Z DEBUG 636 2020-06-17T10:10:53Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-timelimit: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:10:53Z DEBUG 64 2020-06-17T10:10:53Z DEBUG nsslapd-svrtab: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordExp: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordSendExpiringTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG day 2020-06-17T10:10:53Z DEBUG passwordLockoutDuration: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-idletimeout: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-nagle: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-csnlogging: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordCheckSyntax: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-snmp-index: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:10:53Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:10:53Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:10:53Z DEBUG uidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:10:53Z DEBUG gidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:10:53Z DEBUG dc=example,dc=com 2020-06-17T10:10:53Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:10:53Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-counters: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-rootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG passwordMinAge: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-result-tweak: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-maxbersize: 2020-06-17T10:10:53Z DEBUG 209715200 2020-06-17T10:10:53Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-versionstring: 2020-06-17T10:10:53Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-referralmode: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:10:53Z DEBUG 262144 2020-06-17T10:10:53Z DEBUG nsslapd-conntablesize: 2020-06-17T10:10:53Z DEBUG 1024 2020-06-17T10:10:53Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:10:53Z DEBUG allowed 2020-06-17T10:10:53Z DEBUG nsslapd-config: 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-instancedir: 2020-06-17T10:10:53Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-schemadir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:10:53Z DEBUG nsslapd-lockdir: 2020-06-17T10:10:53Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-tmpdir: 2020-06-17T10:10:53Z DEBUG /tmp 2020-06-17T10:10:53Z DEBUG nsslapd-certdir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-ldifdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:10:53Z DEBUG nsslapd-bakdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:10:53Z DEBUG nsslapd-saslpath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rundir: 2020-06-17T10:10:53Z DEBUG /var/run/dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:10:53Z DEBUG 300000 2020-06-17T10:10:53Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-localssf: 2020-06-17T10:10:53Z DEBUG 71 2020-06-17T10:10:53Z DEBUG nsslapd-minssf: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:10:53Z DEBUG next 2020-06-17T10:10:53Z DEBUG nsslapd-validate-cert: 2020-06-17T10:10:53Z DEBUG warn 2020-06-17T10:10:53Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:10:53Z DEBUG 60 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:10:53Z DEBUG 20971520 2020-06-17T10:10:53Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:10:53Z DEBUG nolog 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:10:53Z DEBUG 128 2020-06-17T10:10:53Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:10:53Z DEBUG -1 2020-06-17T10:10:53Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-logging-backend: 2020-06-17T10:10:53Z DEBUG dirsrv-log 2020-06-17T10:10:53Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:10:53Z DEBUG warn-invalid 2020-06-17T10:10:53Z DEBUG passwordStorageScheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG passwordAdminDN: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-hash-filters: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsslapdConfig 2020-06-17T10:10:53Z DEBUG nsslapd-backendconfig: 2020-06-17T10:10:53Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-betype: 2020-06-17T10:10:53Z DEBUG ldbm database 2020-06-17T10:10:53Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:10:53Z DEBUG cn=schema 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG cn=monitor 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-plugin: 2020-06-17T10:10:53Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-port 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 10 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:10:53Z DEBUG 16384 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-port: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-workingdir: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-localuser: 2020-06-17T10:10:53Z DEBUG dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordInHistory: 2020-06-17T10:10:53Z DEBUG 6 2020-06-17T10:10:53Z DEBUG passwordUnlock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordGraceLimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordMustChange: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-sizelimit: 2020-06-17T10:10:53Z DEBUG 2000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordWarning: 2020-06-17T10:10:53Z DEBUG 86400 2020-06-17T10:10:53Z DEBUG nsslapd-readonly: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-threadnumber: 2020-06-17T10:10:53Z DEBUG 16 2020-06-17T10:10:53Z DEBUG passwordLockout: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-localhost: 2020-06-17T10:10:53Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:10:53Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:10:53Z DEBUG 10000 2020-06-17T10:10:53Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:10:53Z DEBUG 40 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordMinLength: 2020-06-17T10:10:53Z DEBUG 8 2020-06-17T10:10:53Z DEBUG passwordMinDigits: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinAlphas: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinUppers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinLowers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinSpecials: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMin8bit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxRepeats: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinCategories: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordMinTokenLength: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordPalindrome: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictCheck: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictPath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordUserAttributes: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordBadWords: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordMaxSequence: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxSeqSets: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxClassChars: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-schemacheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-schemamod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schemareplace: 2020-06-17T10:10:53Z DEBUG replication-only 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 500 2020-06-17T10:10:53Z DEBUG passwordMaxFailure: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:10:53Z DEBUG nsslapd-lastmod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-security: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordMaxAge: 2020-06-17T10:10:53Z DEBUG 8640000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG passwordResetFailureCount: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordLegacyPolicy: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-rootpw: 2020-06-17T10:10:53Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:10:53Z DEBUG passwordChange: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:10:53Z DEBUG 256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-securePort: 2020-06-17T10:10:53Z DEBUG 636 2020-06-17T10:10:53Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-timelimit: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:10:53Z DEBUG 64 2020-06-17T10:10:53Z DEBUG nsslapd-svrtab: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordExp: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordSendExpiringTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG day 2020-06-17T10:10:53Z DEBUG passwordLockoutDuration: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-idletimeout: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-nagle: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-csnlogging: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordCheckSyntax: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-snmp-index: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:10:53Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:10:53Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:10:53Z DEBUG uidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:10:53Z DEBUG gidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:10:53Z DEBUG dc=example,dc=com 2020-06-17T10:10:53Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:10:53Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-counters: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-rootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG passwordMinAge: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-result-tweak: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-maxbersize: 2020-06-17T10:10:53Z DEBUG 209715200 2020-06-17T10:10:53Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-versionstring: 2020-06-17T10:10:53Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-referralmode: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:10:53Z DEBUG 262144 2020-06-17T10:10:53Z DEBUG nsslapd-conntablesize: 2020-06-17T10:10:53Z DEBUG 1024 2020-06-17T10:10:53Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:10:53Z DEBUG allowed 2020-06-17T10:10:53Z DEBUG nsslapd-config: 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-instancedir: 2020-06-17T10:10:53Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-schemadir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:10:53Z DEBUG nsslapd-lockdir: 2020-06-17T10:10:53Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-tmpdir: 2020-06-17T10:10:53Z DEBUG /tmp 2020-06-17T10:10:53Z DEBUG nsslapd-certdir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-ldifdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:10:53Z DEBUG nsslapd-bakdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:10:53Z DEBUG nsslapd-saslpath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rundir: 2020-06-17T10:10:53Z DEBUG /var/run/dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:10:53Z DEBUG 300000 2020-06-17T10:10:53Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-localssf: 2020-06-17T10:10:53Z DEBUG 71 2020-06-17T10:10:53Z DEBUG nsslapd-minssf: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:10:53Z DEBUG next 2020-06-17T10:10:53Z DEBUG nsslapd-validate-cert: 2020-06-17T10:10:53Z DEBUG warn 2020-06-17T10:10:53Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:10:53Z DEBUG 60 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:10:53Z DEBUG 20971520 2020-06-17T10:10:53Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:10:53Z DEBUG nolog 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:10:53Z DEBUG 128 2020-06-17T10:10:53Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:10:53Z DEBUG -1 2020-06-17T10:10:53Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-logging-backend: 2020-06-17T10:10:53Z DEBUG dirsrv-log 2020-06-17T10:10:53Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:10:53Z DEBUG warn-invalid 2020-06-17T10:10:53Z DEBUG passwordStorageScheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG passwordAdminDN: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-hash-filters: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG only: set nsslapd-minssf-exclude-rootdse to 'on', current value ['off'] 2020-06-17T10:10:53Z DEBUG only: updated value ['on'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsslapdConfig 2020-06-17T10:10:53Z DEBUG nsslapd-backendconfig: 2020-06-17T10:10:53Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-betype: 2020-06-17T10:10:53Z DEBUG ldbm database 2020-06-17T10:10:53Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:10:53Z DEBUG cn=schema 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG cn=monitor 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-plugin: 2020-06-17T10:10:53Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-port 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 10 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:10:53Z DEBUG 16384 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-port: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-workingdir: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-localuser: 2020-06-17T10:10:53Z DEBUG dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordInHistory: 2020-06-17T10:10:53Z DEBUG 6 2020-06-17T10:10:53Z DEBUG passwordUnlock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordGraceLimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordMustChange: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-sizelimit: 2020-06-17T10:10:53Z DEBUG 2000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordWarning: 2020-06-17T10:10:53Z DEBUG 86400 2020-06-17T10:10:53Z DEBUG nsslapd-readonly: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-threadnumber: 2020-06-17T10:10:53Z DEBUG 16 2020-06-17T10:10:53Z DEBUG passwordLockout: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-localhost: 2020-06-17T10:10:53Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:10:53Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:10:53Z DEBUG 10000 2020-06-17T10:10:53Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:10:53Z DEBUG 40 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordMinLength: 2020-06-17T10:10:53Z DEBUG 8 2020-06-17T10:10:53Z DEBUG passwordMinDigits: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinAlphas: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinUppers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinLowers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinSpecials: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMin8bit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxRepeats: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinCategories: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordMinTokenLength: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordPalindrome: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictCheck: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictPath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordUserAttributes: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordBadWords: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordMaxSequence: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxSeqSets: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxClassChars: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-schemacheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-schemamod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schemareplace: 2020-06-17T10:10:53Z DEBUG replication-only 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 500 2020-06-17T10:10:53Z DEBUG passwordMaxFailure: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:10:53Z DEBUG nsslapd-lastmod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-security: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordMaxAge: 2020-06-17T10:10:53Z DEBUG 8640000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG passwordResetFailureCount: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordLegacyPolicy: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-rootpw: 2020-06-17T10:10:53Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:10:53Z DEBUG passwordChange: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:10:53Z DEBUG 256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-securePort: 2020-06-17T10:10:53Z DEBUG 636 2020-06-17T10:10:53Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-timelimit: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:10:53Z DEBUG 64 2020-06-17T10:10:53Z DEBUG nsslapd-svrtab: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordExp: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordSendExpiringTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG day 2020-06-17T10:10:53Z DEBUG passwordLockoutDuration: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-idletimeout: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-nagle: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-csnlogging: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordCheckSyntax: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-snmp-index: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:10:53Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:10:53Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:10:53Z DEBUG uidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:10:53Z DEBUG gidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:10:53Z DEBUG dc=example,dc=com 2020-06-17T10:10:53Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:10:53Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-counters: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-rootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG passwordMinAge: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-result-tweak: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-maxbersize: 2020-06-17T10:10:53Z DEBUG 209715200 2020-06-17T10:10:53Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-versionstring: 2020-06-17T10:10:53Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-referralmode: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:10:53Z DEBUG 262144 2020-06-17T10:10:53Z DEBUG nsslapd-conntablesize: 2020-06-17T10:10:53Z DEBUG 1024 2020-06-17T10:10:53Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:10:53Z DEBUG allowed 2020-06-17T10:10:53Z DEBUG nsslapd-config: 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-instancedir: 2020-06-17T10:10:53Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-schemadir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:10:53Z DEBUG nsslapd-lockdir: 2020-06-17T10:10:53Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-tmpdir: 2020-06-17T10:10:53Z DEBUG /tmp 2020-06-17T10:10:53Z DEBUG nsslapd-certdir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-ldifdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:10:53Z DEBUG nsslapd-bakdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:10:53Z DEBUG nsslapd-saslpath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rundir: 2020-06-17T10:10:53Z DEBUG /var/run/dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:10:53Z DEBUG 300000 2020-06-17T10:10:53Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-localssf: 2020-06-17T10:10:53Z DEBUG 71 2020-06-17T10:10:53Z DEBUG nsslapd-minssf: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:10:53Z DEBUG next 2020-06-17T10:10:53Z DEBUG nsslapd-validate-cert: 2020-06-17T10:10:53Z DEBUG warn 2020-06-17T10:10:53Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:10:53Z DEBUG 60 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:10:53Z DEBUG 20971520 2020-06-17T10:10:53Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:10:53Z DEBUG nolog 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:10:53Z DEBUG 128 2020-06-17T10:10:53Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:10:53Z DEBUG -1 2020-06-17T10:10:53Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-logging-backend: 2020-06-17T10:10:53Z DEBUG dirsrv-log 2020-06-17T10:10:53Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:10:53Z DEBUG warn-invalid 2020-06-17T10:10:53Z DEBUG passwordStorageScheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG passwordAdminDN: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-hash-filters: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG [(2, 'nsslapd-minssf-exclude-rootdse', ['on'])] 2020-06-17T10:10:53Z DEBUG Updated 1 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=ipa-winsync,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG ipa-winsync 2020-06-17T10:10:53Z DEBUG ipawinsyncacctdisable: 2020-06-17T10:10:53Z DEBUG both 2020-06-17T10:10:53Z DEBUG ipawinsyncdefaultgroupattr: 2020-06-17T10:10:53Z DEBUG ipaDefaultPrimaryGroup 2020-06-17T10:10:53Z DEBUG ipawinsyncdefaultgroupfilter: 2020-06-17T10:10:53Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2020-06-17T10:10:53Z DEBUG ipawinsyncforcesync: 2020-06-17T10:10:53Z DEBUG true 2020-06-17T10:10:53Z DEBUG ipawinsynchomedirattr: 2020-06-17T10:10:53Z DEBUG ipaHomesRootDir 2020-06-17T10:10:53Z DEBUG ipawinsyncloginshellattr: 2020-06-17T10:10:53Z DEBUG ipaDefaultLoginShell 2020-06-17T10:10:53Z DEBUG ipawinsyncnewentryfilter: 2020-06-17T10:10:53Z DEBUG (cn=ipaConfig) 2020-06-17T10:10:53Z DEBUG ipawinsyncnewuserocattr: 2020-06-17T10:10:53Z DEBUG ipauserobjectclasses 2020-06-17T10:10:53Z DEBUG ipawinsyncrealmattr: 2020-06-17T10:10:53Z DEBUG cn 2020-06-17T10:10:53Z DEBUG ipawinsyncrealmfilter: 2020-06-17T10:10:53Z DEBUG (objectclass=krbRealmContainer) 2020-06-17T10:10:53Z DEBUG ipawinsyncuserattr: 2020-06-17T10:10:53Z DEBUG uidNumber -1 2020-06-17T10:10:53Z DEBUG gidNumber -1 2020-06-17T10:10:53Z DEBUG ipawinsyncuserflatten: 2020-06-17T10:10:53Z DEBUG true 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG ipa winsync plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG ipa-winsync-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG ipa_winsync_plugin_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libipa_winsync 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG preoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG FreeIPA project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG FreeIPA/1.0 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG only: set nsslapd-pluginPrecedence to '60', current value [] 2020-06-17T10:10:53Z DEBUG only: updated value ['60'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG ipa-winsync 2020-06-17T10:10:53Z DEBUG ipawinsyncacctdisable: 2020-06-17T10:10:53Z DEBUG both 2020-06-17T10:10:53Z DEBUG ipawinsyncdefaultgroupattr: 2020-06-17T10:10:53Z DEBUG ipaDefaultPrimaryGroup 2020-06-17T10:10:53Z DEBUG ipawinsyncdefaultgroupfilter: 2020-06-17T10:10:53Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2020-06-17T10:10:53Z DEBUG ipawinsyncforcesync: 2020-06-17T10:10:53Z DEBUG true 2020-06-17T10:10:53Z DEBUG ipawinsynchomedirattr: 2020-06-17T10:10:53Z DEBUG ipaHomesRootDir 2020-06-17T10:10:53Z DEBUG ipawinsyncloginshellattr: 2020-06-17T10:10:53Z DEBUG ipaDefaultLoginShell 2020-06-17T10:10:53Z DEBUG ipawinsyncnewentryfilter: 2020-06-17T10:10:53Z DEBUG (cn=ipaConfig) 2020-06-17T10:10:53Z DEBUG ipawinsyncnewuserocattr: 2020-06-17T10:10:53Z DEBUG ipauserobjectclasses 2020-06-17T10:10:53Z DEBUG ipawinsyncrealmattr: 2020-06-17T10:10:53Z DEBUG cn 2020-06-17T10:10:53Z DEBUG ipawinsyncrealmfilter: 2020-06-17T10:10:53Z DEBUG (objectclass=krbRealmContainer) 2020-06-17T10:10:53Z DEBUG ipawinsyncuserattr: 2020-06-17T10:10:53Z DEBUG uidNumber -1 2020-06-17T10:10:53Z DEBUG gidNumber -1 2020-06-17T10:10:53Z DEBUG ipawinsyncuserflatten: 2020-06-17T10:10:53Z DEBUG true 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG ipa winsync plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG ipa-winsync-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG ipa_winsync_plugin_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libipa_winsync 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG preoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG FreeIPA project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG FreeIPA/1.0 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPrecedence: 2020-06-17T10:10:53Z DEBUG 60 2020-06-17T10:10:53Z DEBUG [(2, 'nsslapd-pluginPrecedence', ['60'])] 2020-06-17T10:10:53Z DEBUG Updated 1 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsslapdConfig 2020-06-17T10:10:53Z DEBUG nsslapd-backendconfig: 2020-06-17T10:10:53Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-betype: 2020-06-17T10:10:53Z DEBUG ldbm database 2020-06-17T10:10:53Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:10:53Z DEBUG cn=schema 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG cn=monitor 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-plugin: 2020-06-17T10:10:53Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-port 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 10 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:10:53Z DEBUG 16384 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-port: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-workingdir: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-localuser: 2020-06-17T10:10:53Z DEBUG dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordInHistory: 2020-06-17T10:10:53Z DEBUG 6 2020-06-17T10:10:53Z DEBUG passwordUnlock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordGraceLimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordMustChange: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-sizelimit: 2020-06-17T10:10:53Z DEBUG 2000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordWarning: 2020-06-17T10:10:53Z DEBUG 86400 2020-06-17T10:10:53Z DEBUG nsslapd-readonly: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-threadnumber: 2020-06-17T10:10:53Z DEBUG 16 2020-06-17T10:10:53Z DEBUG passwordLockout: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-localhost: 2020-06-17T10:10:53Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:10:53Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:10:53Z DEBUG 10000 2020-06-17T10:10:53Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:10:53Z DEBUG 40 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordMinLength: 2020-06-17T10:10:53Z DEBUG 8 2020-06-17T10:10:53Z DEBUG passwordMinDigits: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinAlphas: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinUppers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinLowers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinSpecials: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMin8bit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxRepeats: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinCategories: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordMinTokenLength: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordPalindrome: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictCheck: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictPath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordUserAttributes: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordBadWords: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordMaxSequence: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxSeqSets: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxClassChars: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-schemacheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-schemamod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schemareplace: 2020-06-17T10:10:53Z DEBUG replication-only 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 500 2020-06-17T10:10:53Z DEBUG passwordMaxFailure: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:10:53Z DEBUG nsslapd-lastmod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-security: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordMaxAge: 2020-06-17T10:10:53Z DEBUG 8640000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG passwordResetFailureCount: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordLegacyPolicy: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-rootpw: 2020-06-17T10:10:53Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:10:53Z DEBUG passwordChange: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:10:53Z DEBUG 256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-securePort: 2020-06-17T10:10:53Z DEBUG 636 2020-06-17T10:10:53Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-timelimit: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:10:53Z DEBUG 64 2020-06-17T10:10:53Z DEBUG nsslapd-svrtab: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordExp: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordSendExpiringTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG day 2020-06-17T10:10:53Z DEBUG passwordLockoutDuration: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-idletimeout: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-nagle: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-csnlogging: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordCheckSyntax: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-snmp-index: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:10:53Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:10:53Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:10:53Z DEBUG uidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:10:53Z DEBUG gidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:10:53Z DEBUG dc=example,dc=com 2020-06-17T10:10:53Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:10:53Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-counters: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-rootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG passwordMinAge: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-result-tweak: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-maxbersize: 2020-06-17T10:10:53Z DEBUG 209715200 2020-06-17T10:10:53Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-versionstring: 2020-06-17T10:10:53Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-referralmode: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:10:53Z DEBUG 262144 2020-06-17T10:10:53Z DEBUG nsslapd-conntablesize: 2020-06-17T10:10:53Z DEBUG 1024 2020-06-17T10:10:53Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:10:53Z DEBUG allowed 2020-06-17T10:10:53Z DEBUG nsslapd-config: 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-instancedir: 2020-06-17T10:10:53Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-schemadir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:10:53Z DEBUG nsslapd-lockdir: 2020-06-17T10:10:53Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-tmpdir: 2020-06-17T10:10:53Z DEBUG /tmp 2020-06-17T10:10:53Z DEBUG nsslapd-certdir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-ldifdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:10:53Z DEBUG nsslapd-bakdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:10:53Z DEBUG nsslapd-saslpath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rundir: 2020-06-17T10:10:53Z DEBUG /var/run/dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:10:53Z DEBUG 300000 2020-06-17T10:10:53Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-localssf: 2020-06-17T10:10:53Z DEBUG 71 2020-06-17T10:10:53Z DEBUG nsslapd-minssf: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:10:53Z DEBUG next 2020-06-17T10:10:53Z DEBUG nsslapd-validate-cert: 2020-06-17T10:10:53Z DEBUG warn 2020-06-17T10:10:53Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:10:53Z DEBUG 60 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:10:53Z DEBUG 20971520 2020-06-17T10:10:53Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:10:53Z DEBUG nolog 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:10:53Z DEBUG 128 2020-06-17T10:10:53Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:10:53Z DEBUG -1 2020-06-17T10:10:53Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-logging-backend: 2020-06-17T10:10:53Z DEBUG dirsrv-log 2020-06-17T10:10:53Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:10:53Z DEBUG warn-invalid 2020-06-17T10:10:53Z DEBUG passwordStorageScheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG passwordAdminDN: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-hash-filters: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG only: set nsslapd-sasl-mapping-fallback to 'on', current value ['on'] 2020-06-17T10:10:53Z DEBUG only: updated value ['on'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsslapdConfig 2020-06-17T10:10:53Z DEBUG nsslapd-backendconfig: 2020-06-17T10:10:53Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-betype: 2020-06-17T10:10:53Z DEBUG ldbm database 2020-06-17T10:10:53Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:10:53Z DEBUG cn=schema 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG cn=monitor 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-plugin: 2020-06-17T10:10:53Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-port 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 10 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:10:53Z DEBUG 16384 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-port: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-workingdir: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-localuser: 2020-06-17T10:10:53Z DEBUG dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordInHistory: 2020-06-17T10:10:53Z DEBUG 6 2020-06-17T10:10:53Z DEBUG passwordUnlock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordGraceLimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordMustChange: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-sizelimit: 2020-06-17T10:10:53Z DEBUG 2000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordWarning: 2020-06-17T10:10:53Z DEBUG 86400 2020-06-17T10:10:53Z DEBUG nsslapd-readonly: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-threadnumber: 2020-06-17T10:10:53Z DEBUG 16 2020-06-17T10:10:53Z DEBUG passwordLockout: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-localhost: 2020-06-17T10:10:53Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:10:53Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:10:53Z DEBUG 10000 2020-06-17T10:10:53Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:10:53Z DEBUG 40 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordMinLength: 2020-06-17T10:10:53Z DEBUG 8 2020-06-17T10:10:53Z DEBUG passwordMinDigits: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinAlphas: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinUppers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinLowers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinSpecials: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMin8bit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxRepeats: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinCategories: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordMinTokenLength: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordPalindrome: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictCheck: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictPath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordUserAttributes: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordBadWords: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordMaxSequence: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxSeqSets: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxClassChars: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-schemacheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-schemamod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schemareplace: 2020-06-17T10:10:53Z DEBUG replication-only 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 500 2020-06-17T10:10:53Z DEBUG passwordMaxFailure: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:10:53Z DEBUG nsslapd-lastmod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-security: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordMaxAge: 2020-06-17T10:10:53Z DEBUG 8640000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG passwordResetFailureCount: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordLegacyPolicy: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-rootpw: 2020-06-17T10:10:53Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:10:53Z DEBUG passwordChange: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:10:53Z DEBUG 256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-securePort: 2020-06-17T10:10:53Z DEBUG 636 2020-06-17T10:10:53Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-timelimit: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:10:53Z DEBUG 64 2020-06-17T10:10:53Z DEBUG nsslapd-svrtab: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordExp: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordSendExpiringTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG day 2020-06-17T10:10:53Z DEBUG passwordLockoutDuration: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-idletimeout: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-nagle: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-csnlogging: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordCheckSyntax: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-snmp-index: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:10:53Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:10:53Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:10:53Z DEBUG uidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:10:53Z DEBUG gidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:10:53Z DEBUG dc=example,dc=com 2020-06-17T10:10:53Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:10:53Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-counters: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-rootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG passwordMinAge: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-result-tweak: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-maxbersize: 2020-06-17T10:10:53Z DEBUG 209715200 2020-06-17T10:10:53Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-versionstring: 2020-06-17T10:10:53Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-referralmode: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:10:53Z DEBUG 262144 2020-06-17T10:10:53Z DEBUG nsslapd-conntablesize: 2020-06-17T10:10:53Z DEBUG 1024 2020-06-17T10:10:53Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:10:53Z DEBUG allowed 2020-06-17T10:10:53Z DEBUG nsslapd-config: 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-instancedir: 2020-06-17T10:10:53Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-schemadir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:10:53Z DEBUG nsslapd-lockdir: 2020-06-17T10:10:53Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-tmpdir: 2020-06-17T10:10:53Z DEBUG /tmp 2020-06-17T10:10:53Z DEBUG nsslapd-certdir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-ldifdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:10:53Z DEBUG nsslapd-bakdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:10:53Z DEBUG nsslapd-saslpath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rundir: 2020-06-17T10:10:53Z DEBUG /var/run/dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:10:53Z DEBUG 300000 2020-06-17T10:10:53Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-localssf: 2020-06-17T10:10:53Z DEBUG 71 2020-06-17T10:10:53Z DEBUG nsslapd-minssf: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:10:53Z DEBUG next 2020-06-17T10:10:53Z DEBUG nsslapd-validate-cert: 2020-06-17T10:10:53Z DEBUG warn 2020-06-17T10:10:53Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:10:53Z DEBUG 60 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:10:53Z DEBUG 20971520 2020-06-17T10:10:53Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:10:53Z DEBUG nolog 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:10:53Z DEBUG 128 2020-06-17T10:10:53Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:10:53Z DEBUG -1 2020-06-17T10:10:53Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-logging-backend: 2020-06-17T10:10:53Z DEBUG dirsrv-log 2020-06-17T10:10:53Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:10:53Z DEBUG warn-invalid 2020-06-17T10:10:53Z DEBUG passwordStorageScheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG passwordAdminDN: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-hash-filters: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=Full Principal,cn=mapping,cn=sasl,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=Full Principal,cn=mapping,cn=sasl,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Full Principal 2020-06-17T10:10:53Z DEBUG nsSaslMapBaseDNTemplate: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsSaslMapFilterTemplate: 2020-06-17T10:10:53Z DEBUG (krbPrincipalName=\1@\2) 2020-06-17T10:10:53Z DEBUG nsSaslMapPriority: 2020-06-17T10:10:53Z DEBUG 10 2020-06-17T10:10:53Z DEBUG nsSaslMapRegexString: 2020-06-17T10:10:53Z DEBUG \(.*\)@\(.*\) 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSaslMapping 2020-06-17T10:10:53Z DEBUG addifnew: '10' to nsSaslMapPriority, current value ['10'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=Full Principal,cn=mapping,cn=sasl,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Full Principal 2020-06-17T10:10:53Z DEBUG nsSaslMapBaseDNTemplate: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsSaslMapFilterTemplate: 2020-06-17T10:10:53Z DEBUG (krbPrincipalName=\1@\2) 2020-06-17T10:10:53Z DEBUG nsSaslMapPriority: 2020-06-17T10:10:53Z DEBUG 10 2020-06-17T10:10:53Z DEBUG nsSaslMapRegexString: 2020-06-17T10:10:53Z DEBUG \(.*\)@\(.*\) 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSaslMapping 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=Name Only,cn=mapping,cn=sasl,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=Name Only,cn=mapping,cn=sasl,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Name Only 2020-06-17T10:10:53Z DEBUG nsSaslMapBaseDNTemplate: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsSaslMapFilterTemplate: 2020-06-17T10:10:53Z DEBUG (krbPrincipalName=&@LIN.TEST.LAN) 2020-06-17T10:10:53Z DEBUG nsSaslMapPriority: 2020-06-17T10:10:53Z DEBUG 10 2020-06-17T10:10:53Z DEBUG nsSaslMapRegexString: 2020-06-17T10:10:53Z DEBUG ^[^:@]+$ 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSaslMapping 2020-06-17T10:10:53Z DEBUG addifnew: '10' to nsSaslMapPriority, current value ['10'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=Name Only,cn=mapping,cn=sasl,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Name Only 2020-06-17T10:10:53Z DEBUG nsSaslMapBaseDNTemplate: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsSaslMapFilterTemplate: 2020-06-17T10:10:53Z DEBUG (krbPrincipalName=&@LIN.TEST.LAN) 2020-06-17T10:10:53Z DEBUG nsSaslMapPriority: 2020-06-17T10:10:53Z DEBUG 10 2020-06-17T10:10:53Z DEBUG nsSaslMapRegexString: 2020-06-17T10:10:53Z DEBUG ^[^:@]+$ 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSaslMapping 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsslapdConfig 2020-06-17T10:10:53Z DEBUG nsslapd-backendconfig: 2020-06-17T10:10:53Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-betype: 2020-06-17T10:10:53Z DEBUG ldbm database 2020-06-17T10:10:53Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:10:53Z DEBUG cn=schema 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG cn=monitor 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-plugin: 2020-06-17T10:10:53Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-port 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 10 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:10:53Z DEBUG 16384 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-port: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-workingdir: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-localuser: 2020-06-17T10:10:53Z DEBUG dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordInHistory: 2020-06-17T10:10:53Z DEBUG 6 2020-06-17T10:10:53Z DEBUG passwordUnlock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordGraceLimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordMustChange: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-sizelimit: 2020-06-17T10:10:53Z DEBUG 2000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordWarning: 2020-06-17T10:10:53Z DEBUG 86400 2020-06-17T10:10:53Z DEBUG nsslapd-readonly: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-threadnumber: 2020-06-17T10:10:53Z DEBUG 16 2020-06-17T10:10:53Z DEBUG passwordLockout: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-localhost: 2020-06-17T10:10:53Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:10:53Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:10:53Z DEBUG 10000 2020-06-17T10:10:53Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:10:53Z DEBUG 40 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordMinLength: 2020-06-17T10:10:53Z DEBUG 8 2020-06-17T10:10:53Z DEBUG passwordMinDigits: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinAlphas: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinUppers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinLowers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinSpecials: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMin8bit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxRepeats: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinCategories: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordMinTokenLength: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordPalindrome: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictCheck: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictPath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordUserAttributes: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordBadWords: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordMaxSequence: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxSeqSets: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxClassChars: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-schemacheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-schemamod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schemareplace: 2020-06-17T10:10:53Z DEBUG replication-only 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 500 2020-06-17T10:10:53Z DEBUG passwordMaxFailure: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:10:53Z DEBUG nsslapd-lastmod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-security: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordMaxAge: 2020-06-17T10:10:53Z DEBUG 8640000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG passwordResetFailureCount: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordLegacyPolicy: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-rootpw: 2020-06-17T10:10:53Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:10:53Z DEBUG passwordChange: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:10:53Z DEBUG 256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-securePort: 2020-06-17T10:10:53Z DEBUG 636 2020-06-17T10:10:53Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-timelimit: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:10:53Z DEBUG 64 2020-06-17T10:10:53Z DEBUG nsslapd-svrtab: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordExp: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordSendExpiringTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG day 2020-06-17T10:10:53Z DEBUG passwordLockoutDuration: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-idletimeout: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-nagle: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-csnlogging: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordCheckSyntax: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-snmp-index: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:10:53Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:10:53Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:10:53Z DEBUG uidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:10:53Z DEBUG gidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:10:53Z DEBUG dc=example,dc=com 2020-06-17T10:10:53Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:10:53Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-counters: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-rootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG passwordMinAge: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-result-tweak: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-maxbersize: 2020-06-17T10:10:53Z DEBUG 209715200 2020-06-17T10:10:53Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-versionstring: 2020-06-17T10:10:53Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-referralmode: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:10:53Z DEBUG 262144 2020-06-17T10:10:53Z DEBUG nsslapd-conntablesize: 2020-06-17T10:10:53Z DEBUG 1024 2020-06-17T10:10:53Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:10:53Z DEBUG allowed 2020-06-17T10:10:53Z DEBUG nsslapd-config: 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-instancedir: 2020-06-17T10:10:53Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-schemadir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:10:53Z DEBUG nsslapd-lockdir: 2020-06-17T10:10:53Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-tmpdir: 2020-06-17T10:10:53Z DEBUG /tmp 2020-06-17T10:10:53Z DEBUG nsslapd-certdir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-ldifdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:10:53Z DEBUG nsslapd-bakdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:10:53Z DEBUG nsslapd-saslpath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rundir: 2020-06-17T10:10:53Z DEBUG /var/run/dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:10:53Z DEBUG 300000 2020-06-17T10:10:53Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-localssf: 2020-06-17T10:10:53Z DEBUG 71 2020-06-17T10:10:53Z DEBUG nsslapd-minssf: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:10:53Z DEBUG next 2020-06-17T10:10:53Z DEBUG nsslapd-validate-cert: 2020-06-17T10:10:53Z DEBUG warn 2020-06-17T10:10:53Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:10:53Z DEBUG 60 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:10:53Z DEBUG 20971520 2020-06-17T10:10:53Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:10:53Z DEBUG nolog 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:10:53Z DEBUG 128 2020-06-17T10:10:53Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:10:53Z DEBUG -1 2020-06-17T10:10:53Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-logging-backend: 2020-06-17T10:10:53Z DEBUG dirsrv-log 2020-06-17T10:10:53Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:10:53Z DEBUG warn-invalid 2020-06-17T10:10:53Z DEBUG passwordStorageScheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG passwordAdminDN: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-hash-filters: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG only: set nsslapd-allow-hashed-passwords to 'on', current value ['off'] 2020-06-17T10:10:53Z DEBUG only: updated value ['on'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsslapdConfig 2020-06-17T10:10:53Z DEBUG nsslapd-backendconfig: 2020-06-17T10:10:53Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-betype: 2020-06-17T10:10:53Z DEBUG ldbm database 2020-06-17T10:10:53Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:10:53Z DEBUG cn=schema 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG cn=monitor 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-plugin: 2020-06-17T10:10:53Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-port 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 10 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:10:53Z DEBUG 16384 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-port: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-workingdir: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-localuser: 2020-06-17T10:10:53Z DEBUG dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordInHistory: 2020-06-17T10:10:53Z DEBUG 6 2020-06-17T10:10:53Z DEBUG passwordUnlock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordGraceLimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordMustChange: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-sizelimit: 2020-06-17T10:10:53Z DEBUG 2000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordWarning: 2020-06-17T10:10:53Z DEBUG 86400 2020-06-17T10:10:53Z DEBUG nsslapd-readonly: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-threadnumber: 2020-06-17T10:10:53Z DEBUG 16 2020-06-17T10:10:53Z DEBUG passwordLockout: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-localhost: 2020-06-17T10:10:53Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:10:53Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:10:53Z DEBUG 10000 2020-06-17T10:10:53Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:10:53Z DEBUG 40 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordMinLength: 2020-06-17T10:10:53Z DEBUG 8 2020-06-17T10:10:53Z DEBUG passwordMinDigits: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinAlphas: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinUppers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinLowers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinSpecials: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMin8bit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxRepeats: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinCategories: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordMinTokenLength: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordPalindrome: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictCheck: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictPath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordUserAttributes: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordBadWords: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordMaxSequence: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxSeqSets: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxClassChars: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-schemacheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-schemamod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schemareplace: 2020-06-17T10:10:53Z DEBUG replication-only 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 500 2020-06-17T10:10:53Z DEBUG passwordMaxFailure: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:10:53Z DEBUG nsslapd-lastmod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-security: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordMaxAge: 2020-06-17T10:10:53Z DEBUG 8640000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG passwordResetFailureCount: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordLegacyPolicy: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-rootpw: 2020-06-17T10:10:53Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:10:53Z DEBUG passwordChange: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:10:53Z DEBUG 256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-securePort: 2020-06-17T10:10:53Z DEBUG 636 2020-06-17T10:10:53Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-timelimit: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:10:53Z DEBUG 64 2020-06-17T10:10:53Z DEBUG nsslapd-svrtab: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordExp: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordSendExpiringTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG day 2020-06-17T10:10:53Z DEBUG passwordLockoutDuration: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-idletimeout: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-nagle: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-csnlogging: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordCheckSyntax: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-snmp-index: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:10:53Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:10:53Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:10:53Z DEBUG uidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:10:53Z DEBUG gidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:10:53Z DEBUG dc=example,dc=com 2020-06-17T10:10:53Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:10:53Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-counters: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-rootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG passwordMinAge: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-result-tweak: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-maxbersize: 2020-06-17T10:10:53Z DEBUG 209715200 2020-06-17T10:10:53Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-versionstring: 2020-06-17T10:10:53Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-referralmode: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:10:53Z DEBUG 262144 2020-06-17T10:10:53Z DEBUG nsslapd-conntablesize: 2020-06-17T10:10:53Z DEBUG 1024 2020-06-17T10:10:53Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:10:53Z DEBUG allowed 2020-06-17T10:10:53Z DEBUG nsslapd-config: 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-instancedir: 2020-06-17T10:10:53Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-schemadir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:10:53Z DEBUG nsslapd-lockdir: 2020-06-17T10:10:53Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-tmpdir: 2020-06-17T10:10:53Z DEBUG /tmp 2020-06-17T10:10:53Z DEBUG nsslapd-certdir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-ldifdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:10:53Z DEBUG nsslapd-bakdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:10:53Z DEBUG nsslapd-saslpath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rundir: 2020-06-17T10:10:53Z DEBUG /var/run/dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:10:53Z DEBUG 300000 2020-06-17T10:10:53Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-localssf: 2020-06-17T10:10:53Z DEBUG 71 2020-06-17T10:10:53Z DEBUG nsslapd-minssf: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:10:53Z DEBUG next 2020-06-17T10:10:53Z DEBUG nsslapd-validate-cert: 2020-06-17T10:10:53Z DEBUG warn 2020-06-17T10:10:53Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:10:53Z DEBUG 60 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:10:53Z DEBUG 20971520 2020-06-17T10:10:53Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:10:53Z DEBUG nolog 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:10:53Z DEBUG 128 2020-06-17T10:10:53Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:10:53Z DEBUG -1 2020-06-17T10:10:53Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-logging-backend: 2020-06-17T10:10:53Z DEBUG dirsrv-log 2020-06-17T10:10:53Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:10:53Z DEBUG warn-invalid 2020-06-17T10:10:53Z DEBUG passwordStorageScheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG passwordAdminDN: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-hash-filters: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG [(2, 'nsslapd-allow-hashed-passwords', ['on'])] 2020-06-17T10:10:53Z DEBUG Updated 1 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsslapdConfig 2020-06-17T10:10:53Z DEBUG nsslapd-backendconfig: 2020-06-17T10:10:53Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-betype: 2020-06-17T10:10:53Z DEBUG ldbm database 2020-06-17T10:10:53Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:10:53Z DEBUG cn=schema 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG cn=monitor 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-plugin: 2020-06-17T10:10:53Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-port 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 10 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:10:53Z DEBUG 16384 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-port: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-workingdir: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-localuser: 2020-06-17T10:10:53Z DEBUG dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordInHistory: 2020-06-17T10:10:53Z DEBUG 6 2020-06-17T10:10:53Z DEBUG passwordUnlock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordGraceLimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordMustChange: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-sizelimit: 2020-06-17T10:10:53Z DEBUG 2000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordWarning: 2020-06-17T10:10:53Z DEBUG 86400 2020-06-17T10:10:53Z DEBUG nsslapd-readonly: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-threadnumber: 2020-06-17T10:10:53Z DEBUG 16 2020-06-17T10:10:53Z DEBUG passwordLockout: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-localhost: 2020-06-17T10:10:53Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:10:53Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:10:53Z DEBUG 10000 2020-06-17T10:10:53Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:10:53Z DEBUG 40 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordMinLength: 2020-06-17T10:10:53Z DEBUG 8 2020-06-17T10:10:53Z DEBUG passwordMinDigits: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinAlphas: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinUppers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinLowers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinSpecials: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMin8bit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxRepeats: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinCategories: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordMinTokenLength: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordPalindrome: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictCheck: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictPath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordUserAttributes: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordBadWords: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordMaxSequence: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxSeqSets: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxClassChars: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-schemacheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-schemamod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schemareplace: 2020-06-17T10:10:53Z DEBUG replication-only 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 500 2020-06-17T10:10:53Z DEBUG passwordMaxFailure: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:10:53Z DEBUG nsslapd-lastmod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-security: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordMaxAge: 2020-06-17T10:10:53Z DEBUG 8640000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG passwordResetFailureCount: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordLegacyPolicy: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-rootpw: 2020-06-17T10:10:53Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:10:53Z DEBUG passwordChange: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:10:53Z DEBUG 256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-securePort: 2020-06-17T10:10:53Z DEBUG 636 2020-06-17T10:10:53Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-timelimit: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:10:53Z DEBUG 64 2020-06-17T10:10:53Z DEBUG nsslapd-svrtab: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordExp: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordSendExpiringTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG day 2020-06-17T10:10:53Z DEBUG passwordLockoutDuration: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-idletimeout: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-nagle: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-csnlogging: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordCheckSyntax: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-snmp-index: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:10:53Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:10:53Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:10:53Z DEBUG uidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:10:53Z DEBUG gidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:10:53Z DEBUG dc=example,dc=com 2020-06-17T10:10:53Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:10:53Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-counters: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-rootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG passwordMinAge: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-result-tweak: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-maxbersize: 2020-06-17T10:10:53Z DEBUG 209715200 2020-06-17T10:10:53Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-versionstring: 2020-06-17T10:10:53Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-referralmode: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:10:53Z DEBUG 262144 2020-06-17T10:10:53Z DEBUG nsslapd-conntablesize: 2020-06-17T10:10:53Z DEBUG 1024 2020-06-17T10:10:53Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:10:53Z DEBUG allowed 2020-06-17T10:10:53Z DEBUG nsslapd-config: 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-instancedir: 2020-06-17T10:10:53Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-schemadir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:10:53Z DEBUG nsslapd-lockdir: 2020-06-17T10:10:53Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-tmpdir: 2020-06-17T10:10:53Z DEBUG /tmp 2020-06-17T10:10:53Z DEBUG nsslapd-certdir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-ldifdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:10:53Z DEBUG nsslapd-bakdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:10:53Z DEBUG nsslapd-saslpath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rundir: 2020-06-17T10:10:53Z DEBUG /var/run/dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:10:53Z DEBUG 300000 2020-06-17T10:10:53Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-localssf: 2020-06-17T10:10:53Z DEBUG 71 2020-06-17T10:10:53Z DEBUG nsslapd-minssf: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:10:53Z DEBUG next 2020-06-17T10:10:53Z DEBUG nsslapd-validate-cert: 2020-06-17T10:10:53Z DEBUG warn 2020-06-17T10:10:53Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:10:53Z DEBUG 60 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:10:53Z DEBUG 20971520 2020-06-17T10:10:53Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:10:53Z DEBUG nolog 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:10:53Z DEBUG 128 2020-06-17T10:10:53Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:10:53Z DEBUG -1 2020-06-17T10:10:53Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-logging-backend: 2020-06-17T10:10:53Z DEBUG dirsrv-log 2020-06-17T10:10:53Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:10:53Z DEBUG warn-invalid 2020-06-17T10:10:53Z DEBUG passwordStorageScheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG passwordAdminDN: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-hash-filters: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG only: set nsslapd-ioblocktimeout to '10000', current value ['10000'] 2020-06-17T10:10:53Z DEBUG only: updated value ['10000'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsslapdConfig 2020-06-17T10:10:53Z DEBUG nsslapd-backendconfig: 2020-06-17T10:10:53Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-betype: 2020-06-17T10:10:53Z DEBUG ldbm database 2020-06-17T10:10:53Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:10:53Z DEBUG cn=schema 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG cn=monitor 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-plugin: 2020-06-17T10:10:53Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-port 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 10 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:10:53Z DEBUG 16384 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-port: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-workingdir: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-localuser: 2020-06-17T10:10:53Z DEBUG dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordInHistory: 2020-06-17T10:10:53Z DEBUG 6 2020-06-17T10:10:53Z DEBUG passwordUnlock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordGraceLimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordMustChange: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-sizelimit: 2020-06-17T10:10:53Z DEBUG 2000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordWarning: 2020-06-17T10:10:53Z DEBUG 86400 2020-06-17T10:10:53Z DEBUG nsslapd-readonly: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-threadnumber: 2020-06-17T10:10:53Z DEBUG 16 2020-06-17T10:10:53Z DEBUG passwordLockout: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-localhost: 2020-06-17T10:10:53Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:10:53Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:10:53Z DEBUG 10000 2020-06-17T10:10:53Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:10:53Z DEBUG 40 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordMinLength: 2020-06-17T10:10:53Z DEBUG 8 2020-06-17T10:10:53Z DEBUG passwordMinDigits: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinAlphas: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinUppers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinLowers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinSpecials: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMin8bit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxRepeats: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinCategories: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordMinTokenLength: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordPalindrome: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictCheck: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictPath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordUserAttributes: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordBadWords: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordMaxSequence: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxSeqSets: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxClassChars: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-schemacheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-schemamod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schemareplace: 2020-06-17T10:10:53Z DEBUG replication-only 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 500 2020-06-17T10:10:53Z DEBUG passwordMaxFailure: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:10:53Z DEBUG nsslapd-lastmod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-security: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordMaxAge: 2020-06-17T10:10:53Z DEBUG 8640000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG passwordResetFailureCount: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordLegacyPolicy: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-rootpw: 2020-06-17T10:10:53Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:10:53Z DEBUG passwordChange: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:10:53Z DEBUG 256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-securePort: 2020-06-17T10:10:53Z DEBUG 636 2020-06-17T10:10:53Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-timelimit: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:10:53Z DEBUG 64 2020-06-17T10:10:53Z DEBUG nsslapd-svrtab: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordExp: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordSendExpiringTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG day 2020-06-17T10:10:53Z DEBUG passwordLockoutDuration: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-idletimeout: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-nagle: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-csnlogging: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordCheckSyntax: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-snmp-index: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:10:53Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:10:53Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:10:53Z DEBUG uidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:10:53Z DEBUG gidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:10:53Z DEBUG dc=example,dc=com 2020-06-17T10:10:53Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:10:53Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-counters: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-rootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG passwordMinAge: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-result-tweak: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-maxbersize: 2020-06-17T10:10:53Z DEBUG 209715200 2020-06-17T10:10:53Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-versionstring: 2020-06-17T10:10:53Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-referralmode: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:10:53Z DEBUG 262144 2020-06-17T10:10:53Z DEBUG nsslapd-conntablesize: 2020-06-17T10:10:53Z DEBUG 1024 2020-06-17T10:10:53Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:10:53Z DEBUG allowed 2020-06-17T10:10:53Z DEBUG nsslapd-config: 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-instancedir: 2020-06-17T10:10:53Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-schemadir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:10:53Z DEBUG nsslapd-lockdir: 2020-06-17T10:10:53Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-tmpdir: 2020-06-17T10:10:53Z DEBUG /tmp 2020-06-17T10:10:53Z DEBUG nsslapd-certdir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-ldifdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:10:53Z DEBUG nsslapd-bakdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:10:53Z DEBUG nsslapd-saslpath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rundir: 2020-06-17T10:10:53Z DEBUG /var/run/dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:10:53Z DEBUG 300000 2020-06-17T10:10:53Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-localssf: 2020-06-17T10:10:53Z DEBUG 71 2020-06-17T10:10:53Z DEBUG nsslapd-minssf: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:10:53Z DEBUG next 2020-06-17T10:10:53Z DEBUG nsslapd-validate-cert: 2020-06-17T10:10:53Z DEBUG warn 2020-06-17T10:10:53Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:10:53Z DEBUG 60 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:10:53Z DEBUG 20971520 2020-06-17T10:10:53Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:10:53Z DEBUG nolog 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:10:53Z DEBUG 128 2020-06-17T10:10:53Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:10:53Z DEBUG -1 2020-06-17T10:10:53Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-logging-backend: 2020-06-17T10:10:53Z DEBUG dirsrv-log 2020-06-17T10:10:53Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:10:53Z DEBUG warn-invalid 2020-06-17T10:10:53Z DEBUG passwordStorageScheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG passwordAdminDN: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-hash-filters: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-config.update 0.727 sec 2020-06-17T10:10:53Z DEBUG Parsing update file '/usr/share/ipa/updates/10-enable-betxn.update' 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=7-bit check,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG 7-bit check 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Enforce 7-bit clean attribute values 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG NS7bitAttr 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NS7bitAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpreoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-pluginarg0: 2020-06-17T10:10:53Z DEBUG uid 2020-06-17T10:10:53Z DEBUG nsslapd-pluginarg1: 2020-06-17T10:10:53Z DEBUG mail 2020-06-17T10:10:53Z DEBUG nsslapd-pluginarg2: 2020-06-17T10:10:53Z DEBUG , 2020-06-17T10:10:53Z DEBUG nsslapd-pluginarg3: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2020-06-17T10:10:53Z DEBUG only: updated value ['betxnpreoperation'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG 7-bit check 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Enforce 7-bit clean attribute values 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG NS7bitAttr 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NS7bitAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpreoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-pluginarg0: 2020-06-17T10:10:53Z DEBUG uid 2020-06-17T10:10:53Z DEBUG nsslapd-pluginarg1: 2020-06-17T10:10:53Z DEBUG mail 2020-06-17T10:10:53Z DEBUG nsslapd-pluginarg2: 2020-06-17T10:10:53Z DEBUG , 2020-06-17T10:10:53Z DEBUG nsslapd-pluginarg3: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=attribute uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=attribute uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG attribute uniqueness 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpreoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG uniqueness-across-all-subtrees: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG uniqueness-attribute-name: 2020-06-17T10:10:53Z DEBUG uid 2020-06-17T10:10:53Z DEBUG uniqueness-subtrees: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2020-06-17T10:10:53Z DEBUG only: updated value ['betxnpreoperation'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=attribute uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG attribute uniqueness 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpreoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG uniqueness-across-all-subtrees: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG uniqueness-attribute-name: 2020-06-17T10:10:53Z DEBUG uid 2020-06-17T10:10:53Z DEBUG uniqueness-subtrees: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=Auto Membership Plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG automemberprocessmodifyops: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Auto Membership Plugin 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginConfigArea: 2020-06-17T10:10:53Z DEBUG cn=automember,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Auto Membership plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG Auto Membership 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG automember_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libautomember-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpreoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2020-06-17T10:10:53Z DEBUG only: updated value ['betxnpreoperation'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG automemberprocessmodifyops: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Auto Membership Plugin 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginConfigArea: 2020-06-17T10:10:53Z DEBUG cn=automember,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Auto Membership plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG Auto Membership 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG automember_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libautomember-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpreoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=Linked Attributes,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Linked Attributes 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Linked Attributes plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG Linked Attributes 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG linked_attrs_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG liblinkedattrs-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpreoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2020-06-17T10:10:53Z DEBUG only: updated value ['betxnpreoperation'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Linked Attributes 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Linked Attributes plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG Linked Attributes 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG linked_attrs_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG liblinkedattrs-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpreoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=Managed Entries,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Managed Entries 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginConfigArea: 2020-06-17T10:10:53Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Managed Entries plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG Managed Entries 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG mep_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libmanagedentries-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpreoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2020-06-17T10:10:53Z DEBUG only: updated value ['betxnpreoperation'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Managed Entries 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginConfigArea: 2020-06-17T10:10:53Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Managed Entries plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG Managed Entries 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG mep_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libmanagedentries-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpreoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=MemberOf Plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG MemberOf Plugin 2020-06-17T10:10:53Z DEBUG memberofattr: 2020-06-17T10:10:53Z DEBUG memberOf 2020-06-17T10:10:53Z DEBUG memberofgroupattr: 2020-06-17T10:10:53Z DEBUG member 2020-06-17T10:10:53Z DEBUG memberUser 2020-06-17T10:10:53Z DEBUG memberHost 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG memberof plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG memberof 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG memberof_postop_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libmemberof-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpostoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG only: set nsslapd-pluginType to 'betxnpostoperation', current value ['betxnpostoperation'] 2020-06-17T10:10:53Z DEBUG only: updated value ['betxnpostoperation'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG MemberOf Plugin 2020-06-17T10:10:53Z DEBUG memberofattr: 2020-06-17T10:10:53Z DEBUG memberOf 2020-06-17T10:10:53Z DEBUG memberofgroupattr: 2020-06-17T10:10:53Z DEBUG member 2020-06-17T10:10:53Z DEBUG memberUser 2020-06-17T10:10:53Z DEBUG memberHost 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG memberof plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG memberof 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG memberof_postop_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libmemberof-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpostoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Multimaster Replication Plugin 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-17T10:10:53Z DEBUG ldbm database 2020-06-17T10:10:53Z DEBUG AES 2020-06-17T10:10:53Z DEBUG Class of Service 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Multi-master Replication Plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG replication-multimaster 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG replication_multimaster_plugin_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libreplication-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG object 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value ['on'] 2020-06-17T10:10:53Z DEBUG only: updated value ['on'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Multimaster Replication Plugin 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-17T10:10:53Z DEBUG ldbm database 2020-06-17T10:10:53Z DEBUG AES 2020-06-17T10:10:53Z DEBUG Class of Service 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Multi-master Replication Plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG replication-multimaster 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG replication_multimaster_plugin_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libreplication-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG object 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=PAM Pass Through Auth,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=PAM Pass Through Auth,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG PAM Pass Through Auth 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG pam_passthruauth_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libpam-passthru-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpreoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-pluginloadglobal: 2020-06-17T10:10:53Z DEBUG true 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG pamConfig 2020-06-17T10:10:53Z DEBUG pamExcludeSuffix: 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG pamFallback: 2020-06-17T10:10:53Z DEBUG FALSE 2020-06-17T10:10:53Z DEBUG pamIDAttr: 2020-06-17T10:10:53Z DEBUG notUsedWithRDNMethod 2020-06-17T10:10:53Z DEBUG pamIDMapMethod: 2020-06-17T10:10:53Z DEBUG RDN 2020-06-17T10:10:53Z DEBUG pamMissingSuffix: 2020-06-17T10:10:53Z DEBUG ALLOW 2020-06-17T10:10:53Z DEBUG pamSecure: 2020-06-17T10:10:53Z DEBUG TRUE 2020-06-17T10:10:53Z DEBUG pamService: 2020-06-17T10:10:53Z DEBUG ldapserver 2020-06-17T10:10:53Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2020-06-17T10:10:53Z DEBUG only: updated value ['betxnpreoperation'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=PAM Pass Through Auth,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG PAM Pass Through Auth 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG pam_passthruauth_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libpam-passthru-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpreoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-pluginloadglobal: 2020-06-17T10:10:53Z DEBUG true 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG pamConfig 2020-06-17T10:10:53Z DEBUG pamExcludeSuffix: 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG pamFallback: 2020-06-17T10:10:53Z DEBUG FALSE 2020-06-17T10:10:53Z DEBUG pamIDAttr: 2020-06-17T10:10:53Z DEBUG notUsedWithRDNMethod 2020-06-17T10:10:53Z DEBUG pamIDMapMethod: 2020-06-17T10:10:53Z DEBUG RDN 2020-06-17T10:10:53Z DEBUG pamMissingSuffix: 2020-06-17T10:10:53Z DEBUG ALLOW 2020-06-17T10:10:53Z DEBUG pamSecure: 2020-06-17T10:10:53Z DEBUG TRUE 2020-06-17T10:10:53Z DEBUG pamService: 2020-06-17T10:10:53Z DEBUG ldapserver 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=referential integrity postoperation,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG referential integrity postoperation 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG referential integrity plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG referint 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG referint_postop_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libreferint-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpostoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-pluginprecedence: 2020-06-17T10:10:53Z DEBUG 40 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG referint-logfile: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/referint 2020-06-17T10:10:53Z DEBUG referint-membership-attr: 2020-06-17T10:10:53Z DEBUG member 2020-06-17T10:10:53Z DEBUG uniquemember 2020-06-17T10:10:53Z DEBUG owner 2020-06-17T10:10:53Z DEBUG seeAlso 2020-06-17T10:10:53Z DEBUG referint-update-delay: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG only: set nsslapd-pluginType to 'betxnpostoperation', current value ['betxnpostoperation'] 2020-06-17T10:10:53Z DEBUG only: updated value ['betxnpostoperation'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG referential integrity postoperation 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG referential integrity plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG referint 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG referint_postop_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libreferint-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpostoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-pluginprecedence: 2020-06-17T10:10:53Z DEBUG 40 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG referint-logfile: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/referint 2020-06-17T10:10:53Z DEBUG referint-membership-attr: 2020-06-17T10:10:53Z DEBUG member 2020-06-17T10:10:53Z DEBUG uniquemember 2020-06-17T10:10:53Z DEBUG owner 2020-06-17T10:10:53Z DEBUG seeAlso 2020-06-17T10:10:53Z DEBUG referint-update-delay: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=Roles Plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Roles Plugin 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-17T10:10:53Z DEBUG State Change Plugin 2020-06-17T10:10:53Z DEBUG Views 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG roles plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG roles 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG roles_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libroles-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG object 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value ['on'] 2020-06-17T10:10:53Z DEBUG only: updated value ['on'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Roles Plugin 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-17T10:10:53Z DEBUG State Change Plugin 2020-06-17T10:10:53Z DEBUG Views 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG roles plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG roles 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG roles_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libroles-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG object 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=State Change Plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG State Change Plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG state change notification service plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG statechange 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG statechange_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libstatechange-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpostoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG only: set nsslapd-pluginType to 'betxnpostoperation', current value ['betxnpostoperation'] 2020-06-17T10:10:53Z DEBUG only: updated value ['betxnpostoperation'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG State Change Plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG state change notification service plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG statechange 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG statechange_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libstatechange-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpostoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=USN,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=USN,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG USN 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG USN (Update Sequence Number) plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG USN 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG usn_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libusn-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG object 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value ['on'] 2020-06-17T10:10:53Z DEBUG only: updated value ['on'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=USN,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG USN 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG USN (Update Sequence Number) plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG USN 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG usn_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libusn-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG object 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=IPA MODRDN,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG IPA MODRDN 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG IPA MODRDN plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG IPA MODRDN 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG ipamodrdn_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libipa_modrdn 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpostoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG Red Hat, Inc. 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.0 2020-06-17T10:10:53Z DEBUG nsslapd-pluginprecedence: 2020-06-17T10:10:53Z DEBUG 60 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG only: set nsslapd-plugintype to 'betxnpostoperation', current value ['betxnpostoperation'] 2020-06-17T10:10:53Z DEBUG only: updated value ['betxnpostoperation'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG IPA MODRDN 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG IPA MODRDN plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG IPA MODRDN 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG ipamodrdn_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libipa_modrdn 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpostoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG Red Hat, Inc. 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.0 2020-06-17T10:10:53Z DEBUG nsslapd-pluginprecedence: 2020-06-17T10:10:53Z DEBUG 60 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=ipa_pwd_extop,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG ipa_pwd_extop 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG IPA Password Extended Operation plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG IPA Password Manager 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG ipapwd_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libipa_pwd_extop 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG extendedop 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG FreeIPA project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG FreeIPA/1.0 2020-06-17T10:10:53Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-realmtree: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value ['on'] 2020-06-17T10:10:53Z DEBUG only: updated value ['on'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG ipa_pwd_extop 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG IPA Password Extended Operation plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG IPA Password Manager 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG ipapwd_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libipa_pwd_extop 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG extendedop 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG FreeIPA project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG FreeIPA/1.0 2020-06-17T10:10:53Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-realmtree: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG New entry: cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG onlyifexist: 'on' to nsslapd-pluginbetxn, current value [] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG New entry: cn=NIS Server,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=NIS Server,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG onlyifexist: 'on' to nsslapd-pluginbetxn, current value [] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=NIS Server,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-enable-betxn.update 0.072 sec 2020-06-17T10:10:53Z DEBUG Parsing update file '/usr/share/ipa/updates/10-ipapwd.update' 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=ipa_pwd_extop,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG ipa_pwd_extop 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG IPA Password Extended Operation plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG IPA Password Manager 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG ipapwd_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libipa_pwd_extop 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG extendedop 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG FreeIPA project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG FreeIPA/1.0 2020-06-17T10:10:53Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-realmtree: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG add: '49' to nsslapd-pluginprecedence, current value [] 2020-06-17T10:10:53Z DEBUG add: updated value ['49'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG ipa_pwd_extop 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG IPA Password Extended Operation plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG IPA Password Manager 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG ipapwd_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libipa_pwd_extop 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG extendedop 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG FreeIPA project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG FreeIPA/1.0 2020-06-17T10:10:53Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-realmtree: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsslapd-pluginprecedence: 2020-06-17T10:10:53Z DEBUG 49 2020-06-17T10:10:53Z DEBUG [(2, 'nsslapd-pluginprecedence', ['49'])] 2020-06-17T10:10:53Z DEBUG Updated 1 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-ipapwd.update 0.012 sec 2020-06-17T10:10:53Z DEBUG Parsing update file '/usr/share/ipa/updates/10-rootdse.update' 2020-06-17T10:10:53Z DEBUG Updating existing entry: 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG defaultnamingcontext: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG dataversion: 2020-06-17T10:10:53Z DEBUG 020200617101051020200617101051 2020-06-17T10:10:53Z DEBUG netscapemdsuffix: 2020-06-17T10:10:53Z DEBUG cn=ldap://dc=freeipaserver,dc=lin,dc=test,dc=lan:0 2020-06-17T10:10:53Z DEBUG lastusn: 2020-06-17T10:10:53Z DEBUG 428 2020-06-17T10:10:53Z DEBUG ipatopologypluginversion: 2020-06-17T10:10:53Z DEBUG 1.0 2020-06-17T10:10:53Z DEBUG ipatopologyismanaged: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG ipaDomainLevel: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr != "aci")(version 3.0; aci "rootdse anon read access"; allow(read,search,compare) userdn="ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG add: 'namingContexts' to nsslapd-return-default-opattr, current value [] 2020-06-17T10:10:53Z DEBUG add: updated value ['namingContexts'] 2020-06-17T10:10:53Z DEBUG add: 'supportedControl' to nsslapd-return-default-opattr, current value ['namingContexts'] 2020-06-17T10:10:53Z DEBUG add: updated value ['namingContexts', 'supportedControl'] 2020-06-17T10:10:53Z DEBUG add: 'supportedExtension' to nsslapd-return-default-opattr, current value ['namingContexts', 'supportedControl'] 2020-06-17T10:10:53Z DEBUG add: updated value ['namingContexts', 'supportedControl', 'supportedExtension'] 2020-06-17T10:10:53Z DEBUG add: 'supportedLDAPVersion' to nsslapd-return-default-opattr, current value ['namingContexts', 'supportedControl', 'supportedExtension'] 2020-06-17T10:10:53Z DEBUG add: updated value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion'] 2020-06-17T10:10:53Z DEBUG add: 'supportedSASLMechanisms' to nsslapd-return-default-opattr, current value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion'] 2020-06-17T10:10:53Z DEBUG add: updated value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms'] 2020-06-17T10:10:53Z DEBUG add: 'vendorName' to nsslapd-return-default-opattr, current value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms'] 2020-06-17T10:10:53Z DEBUG add: updated value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms', 'vendorName'] 2020-06-17T10:10:53Z DEBUG add: 'vendorVersion' to nsslapd-return-default-opattr, current value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms', 'vendorName'] 2020-06-17T10:10:53Z DEBUG add: updated value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms', 'vendorName', 'vendorVersion'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG defaultnamingcontext: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG dataversion: 2020-06-17T10:10:53Z DEBUG 020200617101051020200617101051 2020-06-17T10:10:53Z DEBUG netscapemdsuffix: 2020-06-17T10:10:53Z DEBUG cn=ldap://dc=freeipaserver,dc=lin,dc=test,dc=lan:0 2020-06-17T10:10:53Z DEBUG lastusn: 2020-06-17T10:10:53Z DEBUG 428 2020-06-17T10:10:53Z DEBUG ipatopologypluginversion: 2020-06-17T10:10:53Z DEBUG 1.0 2020-06-17T10:10:53Z DEBUG ipatopologyismanaged: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG ipaDomainLevel: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr != "aci")(version 3.0; aci "rootdse anon read access"; allow(read,search,compare) userdn="ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG nsslapd-return-default-opattr: 2020-06-17T10:10:53Z DEBUG namingContexts 2020-06-17T10:10:53Z DEBUG supportedControl 2020-06-17T10:10:53Z DEBUG supportedExtension 2020-06-17T10:10:53Z DEBUG supportedLDAPVersion 2020-06-17T10:10:53Z DEBUG supportedSASLMechanisms 2020-06-17T10:10:53Z DEBUG vendorName 2020-06-17T10:10:53Z DEBUG vendorVersion 2020-06-17T10:10:53Z DEBUG [(2, 'nsslapd-return-default-opattr', ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms', 'vendorName', 'vendorVersion'])] 2020-06-17T10:10:53Z DEBUG Updated 1 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-rootdse.update 0.014 sec 2020-06-17T10:10:53Z DEBUG Parsing update file '/usr/share/ipa/updates/10-selinuxusermap.update' 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=selinux,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=selinux,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG selinux 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=selinux,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG selinux 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=usermap,cn=selinux,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=usermap,cn=selinux,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG usermap 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=usermap,cn=selinux,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG usermap 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-selinuxusermap.update 0.004 sec 2020-06-17T10:10:53Z DEBUG Parsing update file '/usr/share/ipa/updates/10-uniqueness.update' 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=sudorule name uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=sudorule name uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG sudorule name uniqueness 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Enforce unique attribute values 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG preoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG uniqueness-attribute-name: 2020-06-17T10:10:53Z DEBUG cn 2020-06-17T10:10:53Z DEBUG uniqueness-subtrees: 2020-06-17T10:10:53Z DEBUG cn=sudorules,cn=sudo,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=sudorule name uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG sudorule name uniqueness 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Enforce unique attribute values 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG preoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG uniqueness-attribute-name: 2020-06-17T10:10:53Z DEBUG cn 2020-06-17T10:10:53Z DEBUG uniqueness-subtrees: 2020-06-17T10:10:53Z DEBUG cn=sudorules,cn=sudo,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG New entry: cn=certificate store subject uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=certificate store subject uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG certificate store subject uniqueness 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Enforce unique attribute values 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG preoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG uniqueness-attribute-name: 2020-06-17T10:10:53Z DEBUG ipaCertSubject 2020-06-17T10:10:53Z DEBUG uniqueness-subtrees: 2020-06-17T10:10:53Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.1.0 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG Fedora Project 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=certificate store subject uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG certificate store subject uniqueness 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Enforce unique attribute values 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG preoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG uniqueness-attribute-name: 2020-06-17T10:10:53Z DEBUG ipaCertSubject 2020-06-17T10:10:53Z DEBUG uniqueness-subtrees: 2020-06-17T10:10:53Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.1.0 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG Fedora Project 2020-06-17T10:10:53Z DEBUG New entry: cn=certificate store issuer/serial uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=certificate store issuer/serial uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG certificate store issuer/serial uniqueness 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Enforce unique attribute values 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG preoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG uniqueness-attribute-name: 2020-06-17T10:10:53Z DEBUG ipaCertIssuerSerial 2020-06-17T10:10:53Z DEBUG uniqueness-subtrees: 2020-06-17T10:10:53Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.1.0 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG Fedora Project 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=certificate store issuer/serial uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG certificate store issuer/serial uniqueness 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Enforce unique attribute values 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG preoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG uniqueness-attribute-name: 2020-06-17T10:10:53Z DEBUG ipaCertIssuerSerial 2020-06-17T10:10:53Z DEBUG uniqueness-subtrees: 2020-06-17T10:10:53Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.1.0 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG Fedora Project 2020-06-17T10:10:53Z DEBUG New entry: cn=uid uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG uid uniqueness 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG preoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG uniqueness-attribute-name: 2020-06-17T10:10:53Z DEBUG uid 2020-06-17T10:10:53Z DEBUG uniqueness-subtrees: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG uniqueness-exclude-subtrees: 2020-06-17T10:10:53Z DEBUG cn=compat,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG uniqueness-across-all-subtrees: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG uniqueness-subtree-entries-oc: 2020-06-17T10:10:53Z DEBUG posixAccount 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.1.0 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG Fedora Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Enforce unique attribute values 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG uid uniqueness 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG preoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG uniqueness-attribute-name: 2020-06-17T10:10:53Z DEBUG uid 2020-06-17T10:10:53Z DEBUG uniqueness-subtrees: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG uniqueness-exclude-subtrees: 2020-06-17T10:10:53Z DEBUG cn=compat,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG uniqueness-across-all-subtrees: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG uniqueness-subtree-entries-oc: 2020-06-17T10:10:53Z DEBUG posixAccount 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.1.0 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG Fedora Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Enforce unique attribute values 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=uid uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG uid uniqueness 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG preoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG uniqueness-attribute-name: 2020-06-17T10:10:53Z DEBUG uid 2020-06-17T10:10:53Z DEBUG uniqueness-subtrees: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG uniqueness-exclude-subtrees: 2020-06-17T10:10:53Z DEBUG cn=compat,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG uniqueness-across-all-subtrees: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG uniqueness-subtree-entries-oc: 2020-06-17T10:10:53Z DEBUG posixAccount 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.1.0 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG Fedora Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Enforce unique attribute values 2020-06-17T10:10:53Z DEBUG add: 'cn=compat,dc=lin,dc=test,dc=lan' to uniqueness-exclude-subtrees, current value ['cn=compat,dc=lin,dc=test,dc=lan', 'cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan'] 2020-06-17T10:10:53Z DEBUG add: updated value ['cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan', 'cn=compat,dc=lin,dc=test,dc=lan'] 2020-06-17T10:10:53Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan' to uniqueness-exclude-subtrees, current value ['cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan', 'cn=compat,dc=lin,dc=test,dc=lan'] 2020-06-17T10:10:53Z DEBUG add: updated value ['cn=compat,dc=lin,dc=test,dc=lan', 'cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan'] 2020-06-17T10:10:53Z DEBUG remove: 'off' from uniqueness-across-all-subtrees, current value ['on'] 2020-06-17T10:10:53Z DEBUG remove: 'off' not in uniqueness-across-all-subtrees 2020-06-17T10:10:53Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value ['on'] 2020-06-17T10:10:53Z DEBUG add: updated value ['on'] 2020-06-17T10:10:53Z DEBUG add: 'posixAccount' to uniqueness-subtree-entries-oc, current value ['posixAccount'] 2020-06-17T10:10:53Z DEBUG add: updated value ['posixAccount'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG uid uniqueness 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG preoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG uniqueness-attribute-name: 2020-06-17T10:10:53Z DEBUG uid 2020-06-17T10:10:53Z DEBUG uniqueness-subtrees: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG uniqueness-exclude-subtrees: 2020-06-17T10:10:53Z DEBUG cn=compat,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG uniqueness-across-all-subtrees: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG uniqueness-subtree-entries-oc: 2020-06-17T10:10:53Z DEBUG posixAccount 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.1.0 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG Fedora Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Enforce unique attribute values 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=krbPrincipalName uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=krbPrincipalName uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG krbPrincipalName uniqueness 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Enforce unique attribute values 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG preoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG uniqueness-across-all-subtrees: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG uniqueness-attribute-name: 2020-06-17T10:10:53Z DEBUG krbPrincipalName 2020-06-17T10:10:53Z DEBUG uniqueness-exclude-subtrees: 2020-06-17T10:10:53Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG uniqueness-subtrees: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan' to uniqueness-exclude-subtrees, current value ['cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan'] 2020-06-17T10:10:53Z DEBUG add: updated value ['cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan'] 2020-06-17T10:10:53Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value ['on'] 2020-06-17T10:10:53Z DEBUG add: updated value ['on'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=krbPrincipalName uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG krbPrincipalName uniqueness 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Enforce unique attribute values 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG preoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG uniqueness-across-all-subtrees: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG uniqueness-attribute-name: 2020-06-17T10:10:53Z DEBUG krbPrincipalName 2020-06-17T10:10:53Z DEBUG uniqueness-exclude-subtrees: 2020-06-17T10:10:53Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG uniqueness-subtrees: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=krbCanonicalName uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=krbCanonicalName uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG krbCanonicalName uniqueness 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Enforce unique attribute values 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG preoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG uniqueness-across-all-subtrees: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG uniqueness-attribute-name: 2020-06-17T10:10:53Z DEBUG krbCanonicalName 2020-06-17T10:10:53Z DEBUG uniqueness-exclude-subtrees: 2020-06-17T10:10:53Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG uniqueness-subtrees: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan' to uniqueness-exclude-subtrees, current value ['cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan'] 2020-06-17T10:10:53Z DEBUG add: updated value ['cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan'] 2020-06-17T10:10:53Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value ['on'] 2020-06-17T10:10:53Z DEBUG add: updated value ['on'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=krbCanonicalName uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG krbCanonicalName uniqueness 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Enforce unique attribute values 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG preoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG uniqueness-across-all-subtrees: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG uniqueness-attribute-name: 2020-06-17T10:10:53Z DEBUG krbCanonicalName 2020-06-17T10:10:53Z DEBUG uniqueness-exclude-subtrees: 2020-06-17T10:10:53Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG uniqueness-subtrees: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=ipaUniqueID uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=ipaUniqueID uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG ipaUniqueID uniqueness 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Enforce unique attribute values 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG preoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG uniqueness-across-all-subtrees: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG uniqueness-attribute-name: 2020-06-17T10:10:53Z DEBUG ipaUniqueID 2020-06-17T10:10:53Z DEBUG uniqueness-exclude-subtrees: 2020-06-17T10:10:53Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG uniqueness-subtrees: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan' to uniqueness-exclude-subtrees, current value ['cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan'] 2020-06-17T10:10:53Z DEBUG add: updated value ['cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan'] 2020-06-17T10:10:53Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value ['on'] 2020-06-17T10:10:53Z DEBUG add: updated value ['on'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=ipaUniqueID uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG ipaUniqueID uniqueness 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Enforce unique attribute values 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG preoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG uniqueness-across-all-subtrees: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG uniqueness-attribute-name: 2020-06-17T10:10:53Z DEBUG ipaUniqueID 2020-06-17T10:10:53Z DEBUG uniqueness-exclude-subtrees: 2020-06-17T10:10:53Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG uniqueness-subtrees: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG New entry: cn=caacl name uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=caacl name uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG caacl name uniqueness 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Enforce unique attribute values 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG preoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG uniqueness-attribute-name: 2020-06-17T10:10:53Z DEBUG cn 2020-06-17T10:10:53Z DEBUG uniqueness-subtrees: 2020-06-17T10:10:53Z DEBUG cn=caacls,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.1.0 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG Fedora Project 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=caacl name uniqueness,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG caacl name uniqueness 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Enforce unique attribute values 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libattr-unique-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr_Init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG preoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG uniqueness-attribute-name: 2020-06-17T10:10:53Z DEBUG cn 2020-06-17T10:10:53Z DEBUG uniqueness-subtrees: 2020-06-17T10:10:53Z DEBUG cn=caacls,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG NSUniqueAttr 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.1.0 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG Fedora Project 2020-06-17T10:10:53Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-uniqueness.update 0.073 sec 2020-06-17T10:10:53Z DEBUG Parsing update file '/usr/share/ipa/updates/19-managed-entries.update' 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=Managed Entries,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Managed Entries 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginConfigArea: 2020-06-17T10:10:53Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Managed Entries plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG Managed Entries 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG mep_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libmanagedentries-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpreoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG only: set nsslapd-pluginConfigArea to 'cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan', current value ['cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:10:53Z DEBUG only: updated value ['cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Managed Entries 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:53Z DEBUG database 2020-06-17T10:10:53Z DEBUG nsslapd-pluginConfigArea: 2020-06-17T10:10:53Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:53Z DEBUG Managed Entries plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:53Z DEBUG Managed Entries 2020-06-17T10:10:53Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:53Z DEBUG mep_init 2020-06-17T10:10:53Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:53Z DEBUG libmanagedentries-plugin 2020-06-17T10:10:53Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:53Z DEBUG betxnpreoperation 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:53Z DEBUG 389 Project 2020-06-17T10:10:53Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:53Z DEBUG 1.4.2.4 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsSlapdPlugin 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Managed Entries 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Managed Entries 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=Templates,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=Templates,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Templates 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=Templates,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Templates 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Definitions 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG Definitions 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG LDAP update duration: /usr/share/ipa/updates/19-managed-entries.update 0.011 sec 2020-06-17T10:10:53Z DEBUG Parsing update file '/usr/share/ipa/updates/20-aci.update' 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=ng,cn=alt,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=ng,cn=alt,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG ng 2020-06-17T10:10:53Z DEBUG add: '(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)' to aci, current value [] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=ng,cn=alt,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG ng 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";) 2020-06-17T10:10:53Z DEBUG [(2, 'aci', ['(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)'])] 2020-06-17T10:10:53Z DEBUG Updated 1 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG accounts 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2020-06-17T10:10:53Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2020-06-17T10:10:53Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2020-06-17T10:10:53Z DEBUG add: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)'] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG accounts 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2020-06-17T10:10:53Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2020-06-17T10:10:53Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG domain 2020-06-17T10:10:53Z DEBUG pilotObject 2020-06-17T10:10:53Z DEBUG dc: 2020-06-17T10:10:53Z DEBUG lin 2020-06-17T10:10:53Z DEBUG info: 2020-06-17T10:10:53Z DEBUG IPA V2.0 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:10:53Z DEBUG add: '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)'] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG domain 2020-06-17T10:10:53Z DEBUG pilotObject 2020-06-17T10:10:53Z DEBUG dc: 2020-06-17T10:10:53Z DEBUG lin 2020-06-17T10:10:53Z DEBUG info: 2020-06-17T10:10:53Z DEBUG IPA V2.0 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:10:53Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG computers 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG add: '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)' to aci, current value ['(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG computers 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG computers 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG add: '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)' to aci, current value ['(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG computers 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG domain 2020-06-17T10:10:53Z DEBUG pilotObject 2020-06-17T10:10:53Z DEBUG dc: 2020-06-17T10:10:53Z DEBUG lin 2020-06-17T10:10:53Z DEBUG info: 2020-06-17T10:10:53Z DEBUG IPA V2.0 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:10:53Z DEBUG add: '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)'] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG domain 2020-06-17T10:10:53Z DEBUG pilotObject 2020-06-17T10:10:53Z DEBUG dc: 2020-06-17T10:10:53Z DEBUG lin 2020-06-17T10:10:53Z DEBUG info: 2020-06-17T10:10:53Z DEBUG IPA V2.0 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG [(0, 'aci', ['(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)'])] 2020-06-17T10:10:53Z DEBUG Updated 1 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG domain 2020-06-17T10:10:53Z DEBUG pilotObject 2020-06-17T10:10:53Z DEBUG dc: 2020-06-17T10:10:53Z DEBUG lin 2020-06-17T10:10:53Z DEBUG info: 2020-06-17T10:10:53Z DEBUG IPA V2.0 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG add: '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG domain 2020-06-17T10:10:53Z DEBUG pilotObject 2020-06-17T10:10:53Z DEBUG dc: 2020-06-17T10:10:53Z DEBUG lin 2020-06-17T10:10:53Z DEBUG info: 2020-06-17T10:10:53Z DEBUG IPA V2.0 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG [(0, 'aci', ['(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)'])] 2020-06-17T10:10:53Z DEBUG Updated 1 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG domain 2020-06-17T10:10:53Z DEBUG pilotObject 2020-06-17T10:10:53Z DEBUG dc: 2020-06-17T10:10:53Z DEBUG lin 2020-06-17T10:10:53Z DEBUG info: 2020-06-17T10:10:53Z DEBUG IPA V2.0 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG add: '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG domain 2020-06-17T10:10:53Z DEBUG pilotObject 2020-06-17T10:10:53Z DEBUG dc: 2020-06-17T10:10:53Z DEBUG lin 2020-06-17T10:10:53Z DEBUG info: 2020-06-17T10:10:53Z DEBUG IPA V2.0 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:10:53Z DEBUG [(0, 'aci', ['(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)'])] 2020-06-17T10:10:53Z DEBUG Updated 1 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG domain 2020-06-17T10:10:53Z DEBUG pilotObject 2020-06-17T10:10:53Z DEBUG dc: 2020-06-17T10:10:53Z DEBUG lin 2020-06-17T10:10:53Z DEBUG info: 2020-06-17T10:10:53Z DEBUG IPA V2.0 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:10:53Z DEBUG add: '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)'] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG domain 2020-06-17T10:10:53Z DEBUG pilotObject 2020-06-17T10:10:53Z DEBUG dc: 2020-06-17T10:10:53Z DEBUG lin 2020-06-17T10:10:53Z DEBUG info: 2020-06-17T10:10:53Z DEBUG IPA V2.0 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:10:53Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG [(0, 'aci', ['(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'])] 2020-06-17T10:10:53Z DEBUG Updated 1 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=replicas,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG replicas 2020-06-17T10:10:53Z DEBUG remove: '(targetfilter="(objectclass=nsContainer)")(version 3.0; acl "Deny read access to replica configuration"; deny(read, search, compare) userdn = "ldap:///anyone";)' from aci, current value [] 2020-06-17T10:10:53Z DEBUG remove: '(targetfilter="(objectclass=nsContainer)")(version 3.0; acl "Deny read access to replica configuration"; deny(read, search, compare) userdn = "ldap:///anyone";)' not in aci 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG replicas 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG masters 2020-06-17T10:10:53Z DEBUG add: '(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)' to aci, current value [] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG masters 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:10:53Z DEBUG [(2, 'aci', ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)'])] 2020-06-17T10:10:53Z DEBUG Updated 1 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG masters 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:10:53Z DEBUG add: '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)' to aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)'] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG masters 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:10:53Z DEBUG [(0, 'aci', ['(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)'])] 2020-06-17T10:10:53Z DEBUG Updated 1 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG masters 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:10:53Z DEBUG add: '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)'] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG masters 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG [(0, 'aci', ['(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:10:53Z DEBUG Updated 1 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG sysaccounts 2020-06-17T10:10:53Z DEBUG add: '(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value [] 2020-06-17T10:10:53Z DEBUG add: updated value ['(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG nsContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG sysaccounts 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG [(2, 'aci', ['(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:10:53Z DEBUG Updated 1 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG krbContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG kerberos 2020-06-17T10:10:53Z DEBUG add: '(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)' to aci, current value [] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG krbContainer 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG kerberos 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG [(2, 'aci', ['(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)'])] 2020-06-17T10:10:53Z DEBUG Updated 1 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG domain 2020-06-17T10:10:53Z DEBUG pilotObject 2020-06-17T10:10:53Z DEBUG dc: 2020-06-17T10:10:53Z DEBUG lin 2020-06-17T10:10:53Z DEBUG info: 2020-06-17T10:10:53Z DEBUG IPA V2.0 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:10:53Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2020-06-17T10:10:53Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:10:53Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2020-06-17T10:10:53Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:10:53Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2020-06-17T10:10:53Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:10:53Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2020-06-17T10:10:53Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:10:53Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2020-06-17T10:10:53Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:10:53Z DEBUG add: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:10:53Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:10:53Z DEBUG add: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG add: '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG add: '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG add: '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG domain 2020-06-17T10:10:53Z DEBUG pilotObject 2020-06-17T10:10:53Z DEBUG dc: 2020-06-17T10:10:53Z DEBUG lin 2020-06-17T10:10:53Z DEBUG info: 2020-06-17T10:10:53Z DEBUG IPA V2.0 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:10:53Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:10:53Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:10:53Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:53Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG [(0, 'aci', ['(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:10:53Z DEBUG Updated 1 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=tasks,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=tasks,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG tasks 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr=*)(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG add: '(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=tasks,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG tasks 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr=*)(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG (targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG [(0, 'aci', ['(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:10:53Z DEBUG Updated 1 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=mapping tree,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=mapping tree,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG mapping tree 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG add: '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=mapping tree,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG mapping tree 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:10:53Z DEBUG Updated 1 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=mapping tree,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=mapping tree,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG mapping tree 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG add: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG add: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG add: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG add: updated value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG add: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG add: updated value ['(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=mapping tree,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG mapping tree 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=dc\=lin\,dc\=test\,dc\=lan,cn=mapping tree,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=dc\=lin\,dc\=test\,dc\=lan,cn=mapping tree,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG dc\=lin\,dc\=test\,dc\=lan 2020-06-17T10:10:53Z DEBUG nsslapd-backend: 2020-06-17T10:10:53Z DEBUG userRoot 2020-06-17T10:10:53Z DEBUG nsslapd-state: 2020-06-17T10:10:53Z DEBUG backend 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsMappingTree 2020-06-17T10:10:53Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' from aci, current value [] 2020-06-17T10:10:53Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:10:53Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' from aci, current value [] 2020-06-17T10:10:53Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:10:53Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' from aci, current value [] 2020-06-17T10:10:53Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=dc\=lin\,dc\=test\,dc\=lan,cn=mapping tree,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG dc\=lin\,dc\=test\,dc\=lan 2020-06-17T10:10:53Z DEBUG nsslapd-backend: 2020-06-17T10:10:53Z DEBUG userRoot 2020-06-17T10:10:53Z DEBUG nsslapd-state: 2020-06-17T10:10:53Z DEBUG backend 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsMappingTree 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=o\=ipaca,cn=mapping tree,cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=o\=ipaca,cn=mapping tree,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG o=ipaca 2020-06-17T10:10:53Z DEBUG nsslapd-backend: 2020-06-17T10:10:53Z DEBUG ipaca 2020-06-17T10:10:53Z DEBUG nsslapd-state: 2020-06-17T10:10:53Z DEBUG Backend 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsMappingTree 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr=*)(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetattr=*)(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2020-06-17T10:10:53Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:10:53Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetattr=*)(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2020-06-17T10:10:53Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:10:53Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetattr=*)(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2020-06-17T10:10:53Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=o\=ipaca,cn=mapping tree,cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG o=ipaca 2020-06-17T10:10:53Z DEBUG nsslapd-backend: 2020-06-17T10:10:53Z DEBUG ipaca 2020-06-17T10:10:53Z DEBUG nsslapd-state: 2020-06-17T10:10:53Z DEBUG Backend 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsMappingTree 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr=*)(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG [] 2020-06-17T10:10:53Z DEBUG Updated 0 2020-06-17T10:10:53Z DEBUG Done 2020-06-17T10:10:53Z DEBUG Updating existing entry: cn=config 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Initial value 2020-06-17T10:10:53Z DEBUG dn: cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsslapdConfig 2020-06-17T10:10:53Z DEBUG nsslapd-backendconfig: 2020-06-17T10:10:53Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-betype: 2020-06-17T10:10:53Z DEBUG ldbm database 2020-06-17T10:10:53Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:10:53Z DEBUG cn=schema 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG cn=monitor 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-plugin: 2020-06-17T10:10:53Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-port 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 10 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:10:53Z DEBUG 16384 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-port: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-workingdir: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-localuser: 2020-06-17T10:10:53Z DEBUG dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordInHistory: 2020-06-17T10:10:53Z DEBUG 6 2020-06-17T10:10:53Z DEBUG passwordUnlock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordGraceLimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordMustChange: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-sizelimit: 2020-06-17T10:10:53Z DEBUG 2000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordWarning: 2020-06-17T10:10:53Z DEBUG 86400 2020-06-17T10:10:53Z DEBUG nsslapd-readonly: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-threadnumber: 2020-06-17T10:10:53Z DEBUG 16 2020-06-17T10:10:53Z DEBUG passwordLockout: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-localhost: 2020-06-17T10:10:53Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:10:53Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:10:53Z DEBUG 10000 2020-06-17T10:10:53Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:10:53Z DEBUG 40 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordMinLength: 2020-06-17T10:10:53Z DEBUG 8 2020-06-17T10:10:53Z DEBUG passwordMinDigits: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinAlphas: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinUppers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinLowers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinSpecials: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMin8bit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxRepeats: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinCategories: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordMinTokenLength: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordPalindrome: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictCheck: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictPath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordUserAttributes: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordBadWords: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordMaxSequence: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxSeqSets: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxClassChars: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-schemacheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-schemamod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schemareplace: 2020-06-17T10:10:53Z DEBUG replication-only 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 500 2020-06-17T10:10:53Z DEBUG passwordMaxFailure: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:10:53Z DEBUG nsslapd-lastmod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-security: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordMaxAge: 2020-06-17T10:10:53Z DEBUG 8640000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG passwordResetFailureCount: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordLegacyPolicy: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-rootpw: 2020-06-17T10:10:53Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:10:53Z DEBUG passwordChange: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:10:53Z DEBUG 256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-securePort: 2020-06-17T10:10:53Z DEBUG 636 2020-06-17T10:10:53Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-timelimit: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:10:53Z DEBUG 64 2020-06-17T10:10:53Z DEBUG nsslapd-svrtab: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordExp: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordSendExpiringTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG day 2020-06-17T10:10:53Z DEBUG passwordLockoutDuration: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-idletimeout: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-nagle: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-csnlogging: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordCheckSyntax: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-snmp-index: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:10:53Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:10:53Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:10:53Z DEBUG uidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:10:53Z DEBUG gidNumber 2020-06-17T10:10:53Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:10:53Z DEBUG dc=example,dc=com 2020-06-17T10:10:53Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:10:53Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-counters: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-rootdn: 2020-06-17T10:10:53Z DEBUG cn=Directory Manager 2020-06-17T10:10:53Z DEBUG passwordMinAge: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-result-tweak: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-maxbersize: 2020-06-17T10:10:53Z DEBUG 209715200 2020-06-17T10:10:53Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-versionstring: 2020-06-17T10:10:53Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:10:53Z DEBUG nsslapd-referralmode: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:10:53Z DEBUG 262144 2020-06-17T10:10:53Z DEBUG nsslapd-conntablesize: 2020-06-17T10:10:53Z DEBUG 1024 2020-06-17T10:10:53Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:10:53Z DEBUG allowed 2020-06-17T10:10:53Z DEBUG nsslapd-config: 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-instancedir: 2020-06-17T10:10:53Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-schemadir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:10:53Z DEBUG nsslapd-lockdir: 2020-06-17T10:10:53Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-tmpdir: 2020-06-17T10:10:53Z DEBUG /tmp 2020-06-17T10:10:53Z DEBUG nsslapd-certdir: 2020-06-17T10:10:53Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-ldifdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:10:53Z DEBUG nsslapd-bakdir: 2020-06-17T10:10:53Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:10:53Z DEBUG nsslapd-saslpath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rundir: 2020-06-17T10:10:53Z DEBUG /var/run/dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:10:53Z DEBUG 300000 2020-06-17T10:10:53Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-localssf: 2020-06-17T10:10:53Z DEBUG 71 2020-06-17T10:10:53Z DEBUG nsslapd-minssf: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:10:53Z DEBUG next 2020-06-17T10:10:53Z DEBUG nsslapd-validate-cert: 2020-06-17T10:10:53Z DEBUG warn 2020-06-17T10:10:53Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:10:53Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:10:53Z DEBUG 60 2020-06-17T10:10:53Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:10:53Z DEBUG 20971520 2020-06-17T10:10:53Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:10:53Z DEBUG nolog 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:10:53Z DEBUG 2097152 2020-06-17T10:10:53Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:10:53Z DEBUG 128 2020-06-17T10:10:53Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:10:53Z DEBUG -10 2020-06-17T10:10:53Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:10:53Z DEBUG -1 2020-06-17T10:10:53Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:53Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-logging-backend: 2020-06-17T10:10:53Z DEBUG dirsrv-log 2020-06-17T10:10:53Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:10:53Z DEBUG none 2020-06-17T10:10:53Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:10:53Z DEBUG warn-invalid 2020-06-17T10:10:53Z DEBUG passwordStorageScheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG passwordAdminDN: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:10:53Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-hash-filters: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG aci: 2020-06-17T10:10:53Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:53Z DEBUG remove: '(targetattr != aci)(version 3.0; aci "replica admins read access"; allow (read, search, compare) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2020-06-17T10:10:53Z DEBUG remove: '(targetattr != aci)(version 3.0; aci "replica admins read access"; allow (read, search, compare) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:10:53Z DEBUG remove: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:System: Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2020-06-17T10:10:53Z DEBUG remove: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:System: Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:10:53Z DEBUG --------------------------------------------- 2020-06-17T10:10:53Z DEBUG Final value after applying updates 2020-06-17T10:10:53Z DEBUG dn: cn=config 2020-06-17T10:10:53Z DEBUG cn: 2020-06-17T10:10:53Z DEBUG config 2020-06-17T10:10:53Z DEBUG objectClass: 2020-06-17T10:10:53Z DEBUG top 2020-06-17T10:10:53Z DEBUG extensibleObject 2020-06-17T10:10:53Z DEBUG nsslapdConfig 2020-06-17T10:10:53Z DEBUG nsslapd-backendconfig: 2020-06-17T10:10:53Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-betype: 2020-06-17T10:10:53Z DEBUG ldbm database 2020-06-17T10:10:53Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:10:53Z DEBUG cn=schema 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG cn=monitor 2020-06-17T10:10:53Z DEBUG cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-plugin: 2020-06-17T10:10:53Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:10:53Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-port 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:10:53Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:10:53Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:10:53Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 10 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:10:53Z DEBUG 16384 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-port: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-workingdir: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:53Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:10:53Z DEBUG 5 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-localuser: 2020-06-17T10:10:53Z DEBUG dirsrv 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordInHistory: 2020-06-17T10:10:53Z DEBUG 6 2020-06-17T10:10:53Z DEBUG passwordUnlock: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordGraceLimit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG passwordMustChange: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-sizelimit: 2020-06-17T10:10:53Z DEBUG 2000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordWarning: 2020-06-17T10:10:53Z DEBUG 86400 2020-06-17T10:10:53Z DEBUG nsslapd-readonly: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-threadnumber: 2020-06-17T10:10:53Z DEBUG 16 2020-06-17T10:10:53Z DEBUG passwordLockout: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-localhost: 2020-06-17T10:10:53Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:10:53Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:10:53Z DEBUG 10000 2020-06-17T10:10:53Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:10:53Z DEBUG 40 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG passwordMinLength: 2020-06-17T10:10:53Z DEBUG 8 2020-06-17T10:10:53Z DEBUG passwordMinDigits: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinAlphas: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinUppers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinLowers: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinSpecials: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMin8bit: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxRepeats: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMinCategories: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordMinTokenLength: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG passwordPalindrome: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictCheck: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordDictPath: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordUserAttributes: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordBadWords: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG passwordMaxSequence: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxSeqSets: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG passwordMaxClassChars: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:10:53Z DEBUG 1 2020-06-17T10:10:53Z DEBUG nsslapd-schemacheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-schemamod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-schemareplace: 2020-06-17T10:10:53Z DEBUG replication-only 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:10:53Z DEBUG 500 2020-06-17T10:10:53Z DEBUG passwordMaxFailure: 2020-06-17T10:10:53Z DEBUG 3 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog: 2020-06-17T10:10:53Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:10:53Z DEBUG nsslapd-lastmod: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-security: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordMaxAge: 2020-06-17T10:10:53Z DEBUG 8640000 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG passwordResetFailureCount: 2020-06-17T10:10:53Z DEBUG 600 2020-06-17T10:10:53Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG passwordLegacyPolicy: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:10:53Z DEBUG off 2020-06-17T10:10:53Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:10:53Z DEBUG 2 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:10:53Z DEBUG 0 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:10:53Z DEBUG month 2020-06-17T10:10:53Z DEBUG nsslapd-rootpw: 2020-06-17T10:10:53Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:10:53Z DEBUG passwordChange: 2020-06-17T10:10:53Z DEBUG on 2020-06-17T10:10:53Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:10:53Z DEBUG 256 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:10:53Z DEBUG week 2020-06-17T10:10:53Z DEBUG nsslapd-securePort: 2020-06-17T10:10:53Z DEBUG 636 2020-06-17T10:10:53Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:10:53Z DEBUG 2020-06-17T10:10:53Z DEBUG nsslapd-timelimit: 2020-06-17T10:10:53Z DEBUG 3600 2020-06-17T10:10:53Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:10:53Z DEBUG 100 2020-06-17T10:10:53Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:10:53Z DEBUG 64 2020-06-17T10:10:53Z DEBUG nsslapd-svrtab: 2020-06-17T10:10:54Z DEBUG 2020-06-17T10:10:54Z DEBUG passwordExp: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG passwordSendExpiringTime: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:10:54Z DEBUG day 2020-06-17T10:10:54Z DEBUG passwordLockoutDuration: 2020-06-17T10:10:54Z DEBUG 3600 2020-06-17T10:10:54Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:10:54Z DEBUG 100 2020-06-17T10:10:54Z DEBUG nsslapd-idletimeout: 2020-06-17T10:10:54Z DEBUG 3600 2020-06-17T10:10:54Z DEBUG nsslapd-nagle: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:10:54Z DEBUG 5 2020-06-17T10:10:54Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-csnlogging: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:10:54Z DEBUG month 2020-06-17T10:10:54Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG passwordCheckSyntax: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-listenhost: 2020-06-17T10:10:54Z DEBUG 2020-06-17T10:10:54Z DEBUG nsslapd-snmp-index: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:10:54Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:10:54Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:10:54Z DEBUG cn=Directory Manager 2020-06-17T10:10:54Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:10:54Z DEBUG uidNumber 2020-06-17T10:10:54Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:10:54Z DEBUG gidNumber 2020-06-17T10:10:54Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:10:54Z DEBUG dc=example,dc=com 2020-06-17T10:10:54Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:10:54Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG nsslapd-counters: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:10:54Z DEBUG 5 2020-06-17T10:10:54Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:10:54Z DEBUG 2 2020-06-17T10:10:54Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:10:54Z DEBUG 2020-06-17T10:10:54Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:10:54Z DEBUG 5 2020-06-17T10:10:54Z DEBUG nsslapd-rootdn: 2020-06-17T10:10:54Z DEBUG cn=Directory Manager 2020-06-17T10:10:54Z DEBUG passwordMinAge: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG nsslapd-auditlog: 2020-06-17T10:10:54Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:54Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-result-tweak: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-maxbersize: 2020-06-17T10:10:54Z DEBUG 209715200 2020-06-17T10:10:54Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:10:54Z DEBUG 2097152 2020-06-17T10:10:54Z DEBUG nsslapd-versionstring: 2020-06-17T10:10:54Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:10:54Z DEBUG nsslapd-referralmode: 2020-06-17T10:10:54Z DEBUG 2020-06-17T10:10:54Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:10:54Z DEBUG 262144 2020-06-17T10:10:54Z DEBUG nsslapd-conntablesize: 2020-06-17T10:10:54Z DEBUG 1024 2020-06-17T10:10:54Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:10:54Z DEBUG allowed 2020-06-17T10:10:54Z DEBUG nsslapd-config: 2020-06-17T10:10:54Z DEBUG cn=config 2020-06-17T10:10:54Z DEBUG nsslapd-instancedir: 2020-06-17T10:10:54Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:54Z DEBUG nsslapd-schemadir: 2020-06-17T10:10:54Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:10:54Z DEBUG nsslapd-lockdir: 2020-06-17T10:10:54Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:54Z DEBUG nsslapd-tmpdir: 2020-06-17T10:10:54Z DEBUG /tmp 2020-06-17T10:10:54Z DEBUG nsslapd-certdir: 2020-06-17T10:10:54Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:10:54Z DEBUG nsslapd-ldifdir: 2020-06-17T10:10:54Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:10:54Z DEBUG nsslapd-bakdir: 2020-06-17T10:10:54Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:10:54Z DEBUG nsslapd-saslpath: 2020-06-17T10:10:54Z DEBUG 2020-06-17T10:10:54Z DEBUG nsslapd-rundir: 2020-06-17T10:10:54Z DEBUG /var/run/dirsrv 2020-06-17T10:10:54Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:10:54Z DEBUG 300000 2020-06-17T10:10:54Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-localssf: 2020-06-17T10:10:54Z DEBUG 71 2020-06-17T10:10:54Z DEBUG nsslapd-minssf: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:10:54Z DEBUG next 2020-06-17T10:10:54Z DEBUG nsslapd-validate-cert: 2020-06-17T10:10:54Z DEBUG warn 2020-06-17T10:10:54Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:10:54Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:10:54Z DEBUG 2097152 2020-06-17T10:10:54Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:10:54Z DEBUG 60 2020-06-17T10:10:54Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:10:54Z DEBUG 20971520 2020-06-17T10:10:54Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:10:54Z DEBUG 2020-06-17T10:10:54Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:10:54Z DEBUG nolog 2020-06-17T10:10:54Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:10:54Z DEBUG 2097152 2020-06-17T10:10:54Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:10:54Z DEBUG 1 2020-06-17T10:10:54Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:10:54Z DEBUG 128 2020-06-17T10:10:54Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:10:54Z DEBUG -10 2020-06-17T10:10:54Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:10:54Z DEBUG -10 2020-06-17T10:10:54Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:10:54Z DEBUG -10 2020-06-17T10:10:54Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:10:54Z DEBUG -1 2020-06-17T10:10:54Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:10:54Z DEBUG 600 2020-06-17T10:10:54Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:10:54Z DEBUG 1 2020-06-17T10:10:54Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:10:54Z DEBUG 100 2020-06-17T10:10:54Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:10:54Z DEBUG 100 2020-06-17T10:10:54Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:10:54Z DEBUG 1 2020-06-17T10:10:54Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:10:54Z DEBUG 2 2020-06-17T10:10:54Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:10:54Z DEBUG month 2020-06-17T10:10:54Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:10:54Z DEBUG 5 2020-06-17T10:10:54Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:10:54Z DEBUG week 2020-06-17T10:10:54Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:10:54Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:10:54Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-logging-backend: 2020-06-17T10:10:54Z DEBUG dirsrv-log 2020-06-17T10:10:54Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:10:54Z DEBUG none 2020-06-17T10:10:54Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:10:54Z DEBUG warn-invalid 2020-06-17T10:10:54Z DEBUG passwordStorageScheme: 2020-06-17T10:10:54Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:54Z DEBUG passwordAdminDN: 2020-06-17T10:10:54Z DEBUG 2020-06-17T10:10:54Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:10:54Z DEBUG PBKDF2_SHA256 2020-06-17T10:10:54Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:10:54Z DEBUG 2020-06-17T10:10:54Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:10:54Z DEBUG 2020-06-17T10:10:54Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:10:54Z DEBUG 2020-06-17T10:10:54Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-hash-filters: 2020-06-17T10:10:54Z DEBUG off 2020-06-17T10:10:54Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:10:54Z DEBUG 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG domain 2020-06-17T10:10:54Z DEBUG pilotObject 2020-06-17T10:10:54Z DEBUG dc: 2020-06-17T10:10:54Z DEBUG lin 2020-06-17T10:10:54Z DEBUG info: 2020-06-17T10:10:54Z DEBUG IPA V2.0 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:10:54Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:54Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:54Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:10:54Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:10:54Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:54Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:54Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:10:54Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:54Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0; acl "No anonymous access to roles"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0; acl "No anonymous access to roles"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2020-06-17T10:10:54Z DEBUG remove: '(targetattr = "memberOf || memberHost || memberUser")(version 3.0; acl "No anonymous access to member information"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG remove: '(targetattr = "memberOf || memberHost || memberUser")(version 3.0; acl "No anonymous access to member information"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2020-06-17T10:10:54Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,ou=SUDOers,dc=lin,dc=test,dc=lan")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,ou=SUDOers,dc=lin,dc=test,dc=lan")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG domain 2020-06-17T10:10:54Z DEBUG pilotObject 2020-06-17T10:10:54Z DEBUG dc: 2020-06-17T10:10:54Z DEBUG lin 2020-06-17T10:10:54Z DEBUG info: 2020-06-17T10:10:54Z DEBUG IPA V2.0 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:10:54Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:54Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:54Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:10:54Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:10:54Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:54Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:54Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:10:54Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:54Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG hbac 2020-06-17T10:10:54Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to hbac"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [] 2020-06-17T10:10:54Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to hbac"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG hbac 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=sudo,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=sudo,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG sudo 2020-06-17T10:10:54Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [] 2020-06-17T10:10:54Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=sudo,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG sudo 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG accounts 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2020-06-17T10:10:54Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2020-06-17T10:10:54Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2020-06-17T10:10:54Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2020-06-17T10:10:54Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2020-06-17T10:10:54Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2020-06-17T10:10:54Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2020-06-17T10:10:54Z DEBUG add: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)'] 2020-06-17T10:10:54Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)'] 2020-06-17T10:10:54Z DEBUG add: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)'] 2020-06-17T10:10:54Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2020-06-17T10:10:54Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2020-06-17T10:10:54Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)'] 2020-06-17T10:10:54Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)'] 2020-06-17T10:10:54Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)'] 2020-06-17T10:10:54Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)'] 2020-06-17T10:10:54Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)'] 2020-06-17T10:10:54Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)'] 2020-06-17T10:10:54Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG add: '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)'] 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG accounts 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2020-06-17T10:10:54Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2020-06-17T10:10:54Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2020-06-17T10:10:54Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2020-06-17T10:10:54Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2020-06-17T10:10:54Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2020-06-17T10:10:54Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG domain 2020-06-17T10:10:54Z DEBUG pilotObject 2020-06-17T10:10:54Z DEBUG dc: 2020-06-17T10:10:54Z DEBUG lin 2020-06-17T10:10:54Z DEBUG info: 2020-06-17T10:10:54Z DEBUG IPA V2.0 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:10:54Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:54Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:54Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:10:54Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:10:54Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:54Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:54Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:10:54Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:54Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG add: '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)'] 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG domain 2020-06-17T10:10:54Z DEBUG pilotObject 2020-06-17T10:10:54Z DEBUG dc: 2020-06-17T10:10:54Z DEBUG lin 2020-06-17T10:10:54Z DEBUG info: 2020-06-17T10:10:54Z DEBUG IPA V2.0 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:10:54Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:54Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:10:54Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:10:54Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:54Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:54Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:10:54Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:10:54Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG groups 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) 2020-06-17T10:10:54Z DEBUG add: '(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN";)' to aci, current value ['(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";)'] 2020-06-17T10:10:54Z DEBUG add: updated value ['(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";)', '(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN";)'] 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG groups 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) 2020-06-17T10:10:54Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN";) 2020-06-17T10:10:54Z DEBUG [(0, 'aci', ['(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN";)'])] 2020-06-17T10:10:54Z DEBUG Updated 1 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG hostgroups 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) 2020-06-17T10:10:54Z DEBUG add: '(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN";)' to aci, current value ['(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";)'] 2020-06-17T10:10:54Z DEBUG add: updated value ['(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";)', '(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN";)'] 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG hostgroups 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) 2020-06-17T10:10:54Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN";) 2020-06-17T10:10:54Z DEBUG [(0, 'aci', ['(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN";)'])] 2020-06-17T10:10:54Z DEBUG Updated 1 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG services 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-17T10:10:54Z DEBUG remove: '(target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaKrbPrincipal)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)'] 2020-06-17T10:10:54Z DEBUG remove: '(target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaKrbPrincipal)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:10:54Z DEBUG add: '(target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)'] 2020-06-17T10:10:54Z DEBUG add: updated value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG add: '(target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG add: updated value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG services 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-17T10:10:54Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG [(0, 'aci', ['(target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:10:54Z DEBUG Updated 1 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=ranges,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=ranges,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG ranges 2020-06-17T10:10:54Z DEBUG add: '(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)' to aci, current value [] 2020-06-17T10:10:54Z DEBUG add: updated value ['(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=ranges,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG ranges 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (target = "ldap:///cn=*,cn=ranges,cn=etc,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG [(2, 'aci', ['(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:10:54Z DEBUG Updated 1 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG sysaccounts 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG add: '(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG add: updated value ['(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG sysaccounts 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:10:54Z DEBUG Updated 1 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG etc 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG add: '(target = "ldap:///cn=replication,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG add: updated value ['(targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=replication,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG etc 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (target = "ldap:///cn=replication,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=replication,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:10:54Z DEBUG Updated 1 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG ipa 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG ipa 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:10:54Z DEBUG Updated 1 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG ipa 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG add: '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG ipa 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:10:54Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:10:54Z DEBUG Updated 1 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: krbPrincipalName=WELLKNOWN/ANONYMOUS@LIN.TEST.LAN,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: krbPrincipalName=WELLKNOWN/ANONYMOUS@LIN.TEST.LAN,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG krbprincipal 2020-06-17T10:10:54Z DEBUG krbprincipalaux 2020-06-17T10:10:54Z DEBUG krbTicketPolicyAux 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG ipaAllowedOperations 2020-06-17T10:10:54Z DEBUG krbPrincipalName: 2020-06-17T10:10:54Z DEBUG WELLKNOWN/ANONYMOUS@LIN.TEST.LAN 2020-06-17T10:10:54Z DEBUG krbCanonicalName: 2020-06-17T10:10:54Z DEBUG WELLKNOWN/ANONYMOUS@LIN.TEST.LAN 2020-06-17T10:10:54Z DEBUG krbLastPwdChange: 2020-06-17T10:10:54Z DEBUG 20200617100623Z 2020-06-17T10:10:54Z DEBUG krbPrincipalKey: 2020-06-17T10:10:54Z DEBUG XXXXXXXX 2020-06-17T10:10:54Z DEBUG krbExtraData: 2020-06-17T10:10:54Z DEBUG AAIf6+lecm9vdC9hZG1pbkBMSU4uVEVTVC5MQU4A 2020-06-17T10:10:54Z DEBUG ipaAllowedToPerform;read_keys: 2020-06-17T10:10:54Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2020-06-17T10:10:54Z DEBUG addifexist: 'ipaAllowedOperations' to objectclass, current value ['krbprincipal', 'krbprincipalaux', 'krbTicketPolicyAux', 'top', 'ipaAllowedOperations'] 2020-06-17T10:10:54Z DEBUG addifexist: set objectclass to ['krbprincipal', 'krbprincipalaux', 'krbTicketPolicyAux', 'top', 'ipaAllowedOperations', 'ipaAllowedOperations'] 2020-06-17T10:10:54Z DEBUG addifexist: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)' to aci, current value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2020-06-17T10:10:54Z DEBUG addifexist: set aci to ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2020-06-17T10:10:54Z DEBUG addifexist: 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan' to ipaAllowedToPerform;read_keys, current value ['cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:10:54Z DEBUG addifexist: set ipaAllowedToPerform;read_keys to ['cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan', 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: krbPrincipalName=WELLKNOWN/ANONYMOUS@LIN.TEST.LAN,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG krbprincipal 2020-06-17T10:10:54Z DEBUG krbprincipalaux 2020-06-17T10:10:54Z DEBUG krbTicketPolicyAux 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG ipaAllowedOperations 2020-06-17T10:10:54Z DEBUG ipaAllowedOperations 2020-06-17T10:10:54Z DEBUG krbPrincipalName: 2020-06-17T10:10:54Z DEBUG WELLKNOWN/ANONYMOUS@LIN.TEST.LAN 2020-06-17T10:10:54Z DEBUG krbCanonicalName: 2020-06-17T10:10:54Z DEBUG WELLKNOWN/ANONYMOUS@LIN.TEST.LAN 2020-06-17T10:10:54Z DEBUG krbLastPwdChange: 2020-06-17T10:10:54Z DEBUG 20200617100623Z 2020-06-17T10:10:54Z DEBUG krbPrincipalKey: 2020-06-17T10:10:54Z DEBUG XXXXXXXX 2020-06-17T10:10:54Z DEBUG krbExtraData: 2020-06-17T10:10:54Z DEBUG AAIf6+lecm9vdC9hZG1pbkBMSU4uVEVTVC5MQU4A 2020-06-17T10:10:54Z DEBUG ipaAllowedToPerform;read_keys: 2020-06-17T10:10:54Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG aci: 2020-06-17T10:10:54Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2020-06-17T10:10:54Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-aci.update 0.270 sec 2020-06-17T10:10:54Z DEBUG Parsing update file '/usr/share/ipa/updates/20-default_password_policy.update' 2020-06-17T10:10:54Z DEBUG New entry: cn=Default Host Password Policy,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=Default Host Password Policy,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG krbPwdPolicy 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Default Host Password Policy 2020-06-17T10:10:54Z DEBUG krbMinPwdLife: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdMinDiffChars: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdMinLength: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdHistoryLength: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbMaxPwdLife: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdMaxFailure: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdFailureCountInterval: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdLockoutDuration: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=Default Host Password Policy,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG krbPwdPolicy 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Default Host Password Policy 2020-06-17T10:10:54Z DEBUG krbMinPwdLife: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdMinDiffChars: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdMinLength: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdHistoryLength: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbMaxPwdLife: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdMaxFailure: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdFailureCountInterval: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdLockoutDuration: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG New entry: cn=Default Service Password Policy,cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=Default Service Password Policy,cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG krbPwdPolicy 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Default Service Password Policy 2020-06-17T10:10:54Z DEBUG krbMinPwdLife: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdMinDiffChars: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdMinLength: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdHistoryLength: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbMaxPwdLife: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdMaxFailure: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdFailureCountInterval: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdLockoutDuration: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=Default Service Password Policy,cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG krbPwdPolicy 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Default Service Password Policy 2020-06-17T10:10:54Z DEBUG krbMinPwdLife: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdMinDiffChars: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdMinLength: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdHistoryLength: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbMaxPwdLife: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdMaxFailure: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdFailureCountInterval: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdLockoutDuration: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG New entry: cn=Kerberos Service Password Policy,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=Kerberos Service Password Policy,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Kerberos Service Password Policy 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=Kerberos Service Password Policy,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Kerberos Service Password Policy 2020-06-17T10:10:54Z DEBUG New entry: cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG krbPwdPolicy 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Default Kerberos Service Password Policy 2020-06-17T10:10:54Z DEBUG krbMinPwdLife: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdMinDiffChars: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdMinLength: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdHistoryLength: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbMaxPwdLife: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdMaxFailure: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdFailureCountInterval: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdLockoutDuration: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG krbPwdPolicy 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Default Kerberos Service Password Policy 2020-06-17T10:10:54Z DEBUG krbMinPwdLife: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdMinDiffChars: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdMinLength: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdHistoryLength: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbMaxPwdLife: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdMaxFailure: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdFailureCountInterval: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG krbPwdLockoutDuration: 2020-06-17T10:10:54Z DEBUG 0 2020-06-17T10:10:54Z DEBUG New entry: cn=cosTemplates,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=cosTemplates,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectclass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG cosTemplates 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=cosTemplates,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectclass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG cosTemplates 2020-06-17T10:10:54Z DEBUG New entry: cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectclass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cosTemplate 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG krbContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Default Password Policy 2020-06-17T10:10:54Z DEBUG cosPriority: 2020-06-17T10:10:54Z DEBUG 10000000000 2020-06-17T10:10:54Z DEBUG krbPwdPolicyReference: 2020-06-17T10:10:54Z DEBUG cn=Default Host Password Policy,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectclass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cosTemplate 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG krbContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Default Password Policy 2020-06-17T10:10:54Z DEBUG cosPriority: 2020-06-17T10:10:54Z DEBUG 10000000000 2020-06-17T10:10:54Z DEBUG krbPwdPolicyReference: 2020-06-17T10:10:54Z DEBUG cn=Default Host Password Policy,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG New entry: cn=Default Password Policy,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=Default Password Policy,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG description: 2020-06-17T10:10:54Z DEBUG Default Password Policy for Hosts 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG ldapsubentry 2020-06-17T10:10:54Z DEBUG cosSuperDefinition 2020-06-17T10:10:54Z DEBUG cosPointerDefinition 2020-06-17T10:10:54Z DEBUG cosTemplateDn: 2020-06-17T10:10:54Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG cosAttribute: 2020-06-17T10:10:54Z DEBUG krbPwdPolicyReference default 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=Default Password Policy,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG description: 2020-06-17T10:10:54Z DEBUG Default Password Policy for Hosts 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG ldapsubentry 2020-06-17T10:10:54Z DEBUG cosSuperDefinition 2020-06-17T10:10:54Z DEBUG cosPointerDefinition 2020-06-17T10:10:54Z DEBUG cosTemplateDn: 2020-06-17T10:10:54Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG cosAttribute: 2020-06-17T10:10:54Z DEBUG krbPwdPolicyReference default 2020-06-17T10:10:54Z DEBUG New entry: cn=cosTemplates,cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=cosTemplates,cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectclass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG cosTemplates 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=cosTemplates,cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectclass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG cosTemplates 2020-06-17T10:10:54Z DEBUG New entry: cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectclass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cosTemplate 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG krbContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Default Password Policy 2020-06-17T10:10:54Z DEBUG cosPriority: 2020-06-17T10:10:54Z DEBUG 10000000000 2020-06-17T10:10:54Z DEBUG krbPwdPolicyReference: 2020-06-17T10:10:54Z DEBUG cn=Default Service Password Policy,cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectclass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cosTemplate 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG krbContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Default Password Policy 2020-06-17T10:10:54Z DEBUG cosPriority: 2020-06-17T10:10:54Z DEBUG 10000000000 2020-06-17T10:10:54Z DEBUG krbPwdPolicyReference: 2020-06-17T10:10:54Z DEBUG cn=Default Service Password Policy,cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG New entry: cn=Default Password Policy,cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=Default Password Policy,cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG description: 2020-06-17T10:10:54Z DEBUG Default Password Policy for Services 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG ldapsubentry 2020-06-17T10:10:54Z DEBUG cosSuperDefinition 2020-06-17T10:10:54Z DEBUG cosPointerDefinition 2020-06-17T10:10:54Z DEBUG cosTemplateDn: 2020-06-17T10:10:54Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG cosAttribute: 2020-06-17T10:10:54Z DEBUG krbPwdPolicyReference default 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=Default Password Policy,cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG description: 2020-06-17T10:10:54Z DEBUG Default Password Policy for Services 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG ldapsubentry 2020-06-17T10:10:54Z DEBUG cosSuperDefinition 2020-06-17T10:10:54Z DEBUG cosPointerDefinition 2020-06-17T10:10:54Z DEBUG cosTemplateDn: 2020-06-17T10:10:54Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG cosAttribute: 2020-06-17T10:10:54Z DEBUG krbPwdPolicyReference default 2020-06-17T10:10:54Z DEBUG New entry: cn=cosTemplates,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=cosTemplates,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectclass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG cosTemplates 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=cosTemplates,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectclass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG cosTemplates 2020-06-17T10:10:54Z DEBUG New entry: cn=Default Password Policy,cn=cosTemplates,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectclass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cosTemplate 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG krbContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Default Password Policy 2020-06-17T10:10:54Z DEBUG cosPriority: 2020-06-17T10:10:54Z DEBUG 10000000000 2020-06-17T10:10:54Z DEBUG krbPwdPolicyReference: 2020-06-17T10:10:54Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectclass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cosTemplate 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG krbContainer 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Default Password Policy 2020-06-17T10:10:54Z DEBUG cosPriority: 2020-06-17T10:10:54Z DEBUG 10000000000 2020-06-17T10:10:54Z DEBUG krbPwdPolicyReference: 2020-06-17T10:10:54Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG New entry: cn=Default Password Policy,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=Default Password Policy,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG description: 2020-06-17T10:10:54Z DEBUG Default Password Policy for Kerberos Services 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG ldapsubentry 2020-06-17T10:10:54Z DEBUG cosSuperDefinition 2020-06-17T10:10:54Z DEBUG cosPointerDefinition 2020-06-17T10:10:54Z DEBUG cosTemplateDn: 2020-06-17T10:10:54Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG cosAttribute: 2020-06-17T10:10:54Z DEBUG krbPwdPolicyReference default 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=Default Password Policy,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG description: 2020-06-17T10:10:54Z DEBUG Default Password Policy for Kerberos Services 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG ldapsubentry 2020-06-17T10:10:54Z DEBUG cosSuperDefinition 2020-06-17T10:10:54Z DEBUG cosPointerDefinition 2020-06-17T10:10:54Z DEBUG cosTemplateDn: 2020-06-17T10:10:54Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG cosAttribute: 2020-06-17T10:10:54Z DEBUG krbPwdPolicyReference default 2020-06-17T10:10:54Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-default_password_policy.update 0.098 sec 2020-06-17T10:10:54Z DEBUG Parsing update file '/usr/share/ipa/updates/20-dna.update' 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=ipa-winsync,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG ipa-winsync 2020-06-17T10:10:54Z DEBUG ipawinsyncacctdisable: 2020-06-17T10:10:54Z DEBUG both 2020-06-17T10:10:54Z DEBUG ipawinsyncdefaultgroupattr: 2020-06-17T10:10:54Z DEBUG ipaDefaultPrimaryGroup 2020-06-17T10:10:54Z DEBUG ipawinsyncdefaultgroupfilter: 2020-06-17T10:10:54Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2020-06-17T10:10:54Z DEBUG ipawinsyncforcesync: 2020-06-17T10:10:54Z DEBUG true 2020-06-17T10:10:54Z DEBUG ipawinsynchomedirattr: 2020-06-17T10:10:54Z DEBUG ipaHomesRootDir 2020-06-17T10:10:54Z DEBUG ipawinsyncloginshellattr: 2020-06-17T10:10:54Z DEBUG ipaDefaultLoginShell 2020-06-17T10:10:54Z DEBUG ipawinsyncnewentryfilter: 2020-06-17T10:10:54Z DEBUG (cn=ipaConfig) 2020-06-17T10:10:54Z DEBUG ipawinsyncnewuserocattr: 2020-06-17T10:10:54Z DEBUG ipauserobjectclasses 2020-06-17T10:10:54Z DEBUG ipawinsyncrealmattr: 2020-06-17T10:10:54Z DEBUG cn 2020-06-17T10:10:54Z DEBUG ipawinsyncrealmfilter: 2020-06-17T10:10:54Z DEBUG (objectclass=krbRealmContainer) 2020-06-17T10:10:54Z DEBUG ipawinsyncuserattr: 2020-06-17T10:10:54Z DEBUG uidNumber -1 2020-06-17T10:10:54Z DEBUG gidNumber -1 2020-06-17T10:10:54Z DEBUG ipawinsyncuserflatten: 2020-06-17T10:10:54Z DEBUG true 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG ipa winsync plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG ipa-winsync-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG ipa_winsync_plugin_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libipa_winsync 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG preoperation 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG FreeIPA project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG FreeIPA/1.0 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG nsslapd-pluginprecedence: 2020-06-17T10:10:54Z DEBUG 60 2020-06-17T10:10:54Z DEBUG remove: 'uidNumber 999' from ipaWinSyncUserAttr, current value ['uidNumber -1', 'gidNumber -1'] 2020-06-17T10:10:54Z DEBUG remove: 'uidNumber 999' not in ipaWinSyncUserAttr 2020-06-17T10:10:54Z DEBUG remove: 'gidNumber 999' from ipaWinSyncUserAttr, current value ['uidNumber -1', 'gidNumber -1'] 2020-06-17T10:10:54Z DEBUG remove: 'gidNumber 999' not in ipaWinSyncUserAttr 2020-06-17T10:10:54Z DEBUG add: 'uidNumber -1' to ipaWinSyncUserAttr, current value ['uidNumber -1', 'gidNumber -1'] 2020-06-17T10:10:54Z DEBUG add: updated value ['gidNumber -1', 'uidNumber -1'] 2020-06-17T10:10:54Z DEBUG add: 'gidNumber -1' to ipaWinSyncUserAttr, current value ['gidNumber -1', 'uidNumber -1'] 2020-06-17T10:10:54Z DEBUG add: updated value ['uidNumber -1', 'gidNumber -1'] 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG ipa-winsync 2020-06-17T10:10:54Z DEBUG ipawinsyncacctdisable: 2020-06-17T10:10:54Z DEBUG both 2020-06-17T10:10:54Z DEBUG ipawinsyncdefaultgroupattr: 2020-06-17T10:10:54Z DEBUG ipaDefaultPrimaryGroup 2020-06-17T10:10:54Z DEBUG ipawinsyncdefaultgroupfilter: 2020-06-17T10:10:54Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2020-06-17T10:10:54Z DEBUG ipawinsyncforcesync: 2020-06-17T10:10:54Z DEBUG true 2020-06-17T10:10:54Z DEBUG ipawinsynchomedirattr: 2020-06-17T10:10:54Z DEBUG ipaHomesRootDir 2020-06-17T10:10:54Z DEBUG ipawinsyncloginshellattr: 2020-06-17T10:10:54Z DEBUG ipaDefaultLoginShell 2020-06-17T10:10:54Z DEBUG ipawinsyncnewentryfilter: 2020-06-17T10:10:54Z DEBUG (cn=ipaConfig) 2020-06-17T10:10:54Z DEBUG ipawinsyncnewuserocattr: 2020-06-17T10:10:54Z DEBUG ipauserobjectclasses 2020-06-17T10:10:54Z DEBUG ipawinsyncrealmattr: 2020-06-17T10:10:54Z DEBUG cn 2020-06-17T10:10:54Z DEBUG ipawinsyncrealmfilter: 2020-06-17T10:10:54Z DEBUG (objectclass=krbRealmContainer) 2020-06-17T10:10:54Z DEBUG ipawinsyncuserattr: 2020-06-17T10:10:54Z DEBUG uidNumber -1 2020-06-17T10:10:54Z DEBUG gidNumber -1 2020-06-17T10:10:54Z DEBUG ipawinsyncuserflatten: 2020-06-17T10:10:54Z DEBUG true 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG ipa winsync plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG ipa-winsync-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG ipa_winsync_plugin_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libipa_winsync 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG preoperation 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG FreeIPA project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG FreeIPA/1.0 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG nsslapd-pluginprecedence: 2020-06-17T10:10:54Z DEBUG 60 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-dna.update 0.010 sec 2020-06-17T10:10:54Z DEBUG Parsing update file '/usr/share/ipa/updates/20-enable_dirsrv_plugins.update' 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=7-bit check,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG 7-bit check 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG Enforce 7-bit clean attribute values 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG NS7bitAttr 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG NS7bitAttr_Init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libattr-unique-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG betxnpreoperation 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG nsslapd-pluginarg0: 2020-06-17T10:10:54Z DEBUG uid 2020-06-17T10:10:54Z DEBUG nsslapd-pluginarg1: 2020-06-17T10:10:54Z DEBUG mail 2020-06-17T10:10:54Z DEBUG nsslapd-pluginarg2: 2020-06-17T10:10:54Z DEBUG , 2020-06-17T10:10:54Z DEBUG nsslapd-pluginarg3: 2020-06-17T10:10:54Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG replace: off not found, skipping 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG 7-bit check 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG Enforce 7-bit clean attribute values 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG NS7bitAttr 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG NS7bitAttr_Init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libattr-unique-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG betxnpreoperation 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG nsslapd-pluginarg0: 2020-06-17T10:10:54Z DEBUG uid 2020-06-17T10:10:54Z DEBUG nsslapd-pluginarg1: 2020-06-17T10:10:54Z DEBUG mail 2020-06-17T10:10:54Z DEBUG nsslapd-pluginarg2: 2020-06-17T10:10:54Z DEBUG , 2020-06-17T10:10:54Z DEBUG nsslapd-pluginarg3: 2020-06-17T10:10:54Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=Account Usability Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=Account Usability Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Account Usability Plugin 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG Account Usability Control plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG Account Usability Control 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG auc_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libacctusability-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG preoperation 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG replace: off not found, skipping 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=Account Usability Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Account Usability Plugin 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG Account Usability Control plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG Account Usability Control 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG auc_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libacctusability-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG preoperation 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=ACL Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=ACL Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG ACL Plugin 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG acl access check plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG acl 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG acl_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libacl-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG accesscontrol 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG replace: off not found, skipping 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=ACL Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG ACL Plugin 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG acl access check plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG acl 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG acl_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libacl-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG accesscontrol 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=ACL preoperation,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=ACL preoperation,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG ACL preoperation 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG acl access check plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG acl 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG acl_preopInit 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libacl-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG preoperation 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG replace: off not found, skipping 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=ACL preoperation,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG ACL preoperation 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG acl access check plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG acl 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG acl_preopInit 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libacl-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG preoperation 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=Auto Membership Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG automemberprocessmodifyops: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Auto Membership Plugin 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginConfigArea: 2020-06-17T10:10:54Z DEBUG cn=automember,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG Auto Membership plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG Auto Membership 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG automember_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libautomember-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG betxnpreoperation 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG replace: off not found, skipping 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG automemberprocessmodifyops: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Auto Membership Plugin 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginConfigArea: 2020-06-17T10:10:54Z DEBUG cn=automember,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG Auto Membership plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG Auto Membership 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG automember_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libautomember-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG betxnpreoperation 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=Bitwise Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=Bitwise Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Bitwise Plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG bitwise match plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG bitwise 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG bitwise_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libbitwise-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG matchingRule 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG replace: off not found, skipping 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=Bitwise Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Bitwise Plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG bitwise match plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG bitwise 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG bitwise_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libbitwise-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG matchingRule 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=chaining database,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=chaining database,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG chaining database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG LDAP chaining backend database plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG chaining database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG chaining_back_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libchainingdb-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG replace: off not found, skipping 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=chaining database,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG chaining database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG LDAP chaining backend database plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG chaining database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG chaining_back_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libchainingdb-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=Class of Service,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=Class of Service,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Class of Service 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-17T10:10:54Z DEBUG State Change Plugin 2020-06-17T10:10:54Z DEBUG Views 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG class of service plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG cos 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG cos_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libcos-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG object 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG replace: off not found, skipping 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=Class of Service,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Class of Service 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-17T10:10:54Z DEBUG State Change Plugin 2020-06-17T10:10:54Z DEBUG Views 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG class of service plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG cos 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG cos_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libcos-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG object 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=deref,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=deref,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG deref 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG Dereference plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG Dereference 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG deref_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libderef-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG preoperation 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG replace: off not found, skipping 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=deref,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG deref 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG Dereference plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG Dereference 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG deref_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libderef-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG preoperation 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=HTTP Client,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=HTTP Client,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG HTTP Client 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG HTTP Client plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG http-client 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG http_client_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libhttp-client-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG preoperation 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG replace: off not found, skipping 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=HTTP Client,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG HTTP Client 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG HTTP Client plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG http-client 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG http_client_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libhttp-client-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG preoperation 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=Internationalization Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=Internationalization Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Internationalization Plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG internationalized ordering rule plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG orderingrule 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG orderingRule_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libcollation-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG matchingRule 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG nsslapd-pluginarg0: 2020-06-17T10:10:54Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/slapd-collations.conf 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG replace: off not found, skipping 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=Internationalization Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Internationalization Plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG internationalized ordering rule plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG orderingrule 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG orderingRule_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libcollation-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG matchingRule 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG nsslapd-pluginarg0: 2020-06-17T10:10:54Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/slapd-collations.conf 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=Linked Attributes,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Linked Attributes 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG Linked Attributes plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG Linked Attributes 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG linked_attrs_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG liblinkedattrs-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG betxnpreoperation 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG replace: off not found, skipping 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Linked Attributes 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG Linked Attributes plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG Linked Attributes 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG linked_attrs_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG liblinkedattrs-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG betxnpreoperation 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=Managed Entries,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Managed Entries 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginConfigArea: 2020-06-17T10:10:54Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG Managed Entries plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG Managed Entries 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG mep_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libmanagedentries-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG betxnpreoperation 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG replace: off not found, skipping 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Managed Entries 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginConfigArea: 2020-06-17T10:10:54Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG Managed Entries plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG Managed Entries 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG mep_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libmanagedentries-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG betxnpreoperation 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG nsContainer 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Multimaster Replication Plugin 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-17T10:10:54Z DEBUG ldbm database 2020-06-17T10:10:54Z DEBUG AES 2020-06-17T10:10:54Z DEBUG Class of Service 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG Multi-master Replication Plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG replication-multimaster 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG replication_multimaster_plugin_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libreplication-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG object 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG replace: off not found, skipping 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Multimaster Replication Plugin 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-17T10:10:54Z DEBUG ldbm database 2020-06-17T10:10:54Z DEBUG AES 2020-06-17T10:10:54Z DEBUG Class of Service 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG Multi-master Replication Plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG replication-multimaster 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG replication_multimaster_plugin_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libreplication-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG object 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=Roles Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Roles Plugin 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-17T10:10:54Z DEBUG State Change Plugin 2020-06-17T10:10:54Z DEBUG Views 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG roles plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG roles 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG roles_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libroles-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG object 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG replace: off not found, skipping 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Roles Plugin 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-17T10:10:54Z DEBUG State Change Plugin 2020-06-17T10:10:54Z DEBUG Views 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG roles plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG roles 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG roles_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libroles-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG object 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=Schema Reload,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=Schema Reload,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Schema Reload 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG task plugin to reload schema files 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG schemareload 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG schemareload_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libschemareload-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG object 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG replace: off not found, skipping 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=Schema Reload,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Schema Reload 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG task plugin to reload schema files 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG schemareload 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG schemareload_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libschemareload-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG object 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=State Change Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG State Change Plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG state change notification service plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG statechange 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG statechange_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libstatechange-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG betxnpostoperation 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG replace: off not found, skipping 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG State Change Plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG state change notification service plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG statechange 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG statechange_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libstatechange-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG betxnpostoperation 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=Views,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=Views,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Views 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-17T10:10:54Z DEBUG State Change Plugin 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG virtual directory information tree views plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG views 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG views_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libviews-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG object 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG replace: off not found, skipping 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=Views,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG Views 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-17T10:10:54Z DEBUG State Change Plugin 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG virtual directory information tree views plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG views 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG views_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libviews-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG object 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=whoami,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG whoami 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG whoami extended operation plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG whoami-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG whoami_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libwhoami-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG extendedop 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG replace: off not found, skipping 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG whoami 2020-06-17T10:10:54Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:10:54Z DEBUG database 2020-06-17T10:10:54Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:10:54Z DEBUG whoami extended operation plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:10:54Z DEBUG on 2020-06-17T10:10:54Z DEBUG nsslapd-pluginId: 2020-06-17T10:10:54Z DEBUG whoami-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:10:54Z DEBUG whoami_init 2020-06-17T10:10:54Z DEBUG nsslapd-pluginPath: 2020-06-17T10:10:54Z DEBUG libwhoami-plugin 2020-06-17T10:10:54Z DEBUG nsslapd-pluginType: 2020-06-17T10:10:54Z DEBUG extendedop 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:10:54Z DEBUG 389 Project 2020-06-17T10:10:54Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:10:54Z DEBUG 1.4.2.4 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsSlapdPlugin 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-enable_dirsrv_plugins.update 0.085 sec 2020-06-17T10:10:54Z DEBUG Parsing update file '/usr/share/ipa/updates/20-host_nis_groups.update' 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG mepTemplateEntry 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG NGP HGP Template 2020-06-17T10:10:54Z DEBUG mepRDNAttr: 2020-06-17T10:10:54Z DEBUG cn 2020-06-17T10:10:54Z DEBUG mepStaticAttr: 2020-06-17T10:10:54Z DEBUG ipaUniqueId: autogenerate 2020-06-17T10:10:54Z DEBUG objectclass: ipanisnetgroup 2020-06-17T10:10:54Z DEBUG objectclass: ipaobject 2020-06-17T10:10:54Z DEBUG nisDomainName: lin.test.lan 2020-06-17T10:10:54Z DEBUG mepMappedAttr: 2020-06-17T10:10:54Z DEBUG cn: $cn 2020-06-17T10:10:54Z DEBUG memberHost: $dn 2020-06-17T10:10:54Z DEBUG description: ipaNetgroup $cn 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG mepTemplateEntry 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG NGP HGP Template 2020-06-17T10:10:54Z DEBUG mepRDNAttr: 2020-06-17T10:10:54Z DEBUG cn 2020-06-17T10:10:54Z DEBUG mepStaticAttr: 2020-06-17T10:10:54Z DEBUG ipaUniqueId: autogenerate 2020-06-17T10:10:54Z DEBUG objectclass: ipanisnetgroup 2020-06-17T10:10:54Z DEBUG objectclass: ipaobject 2020-06-17T10:10:54Z DEBUG nisDomainName: lin.test.lan 2020-06-17T10:10:54Z DEBUG mepMappedAttr: 2020-06-17T10:10:54Z DEBUG cn: $cn 2020-06-17T10:10:54Z DEBUG memberHost: $dn 2020-06-17T10:10:54Z DEBUG description: ipaNetgroup $cn 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG NGP Definition 2020-06-17T10:10:54Z DEBUG originScope: 2020-06-17T10:10:54Z DEBUG cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG originFilter: 2020-06-17T10:10:54Z DEBUG objectclass=ipahostgroup 2020-06-17T10:10:54Z DEBUG managedBase: 2020-06-17T10:10:54Z DEBUG cn=ng,cn=alt,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG managedTemplate: 2020-06-17T10:10:54Z DEBUG cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG only: set cn to 'NGP Definition', current value ['NGP Definition'] 2020-06-17T10:10:54Z DEBUG only: updated value ['NGP Definition'] 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG extensibleObject 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG NGP Definition 2020-06-17T10:10:54Z DEBUG originScope: 2020-06-17T10:10:54Z DEBUG cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG originFilter: 2020-06-17T10:10:54Z DEBUG objectclass=ipahostgroup 2020-06-17T10:10:54Z DEBUG managedBase: 2020-06-17T10:10:54Z DEBUG cn=ng,cn=alt,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG managedTemplate: 2020-06-17T10:10:54Z DEBUG cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:54Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-host_nis_groups.update 0.007 sec 2020-06-17T10:10:54Z DEBUG Parsing update file '/usr/share/ipa/updates/20-idoverride_index.update' 2020-06-17T10:10:54Z DEBUG New entry: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG ipaOriginalUid 2020-06-17T10:10:54Z DEBUG ObjectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsIndex 2020-06-17T10:10:54Z DEBUG nsSystemIndex: 2020-06-17T10:10:54Z DEBUG false 2020-06-17T10:10:54Z DEBUG only: set nsIndexType to 'eq', current value [] 2020-06-17T10:10:54Z DEBUG only: updated value ['eq'] 2020-06-17T10:10:54Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:10:54Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG ipaOriginalUid 2020-06-17T10:10:54Z DEBUG ObjectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsIndex 2020-06-17T10:10:54Z DEBUG nsSystemIndex: 2020-06-17T10:10:54Z DEBUG false 2020-06-17T10:10:54Z DEBUG nsIndexType: 2020-06-17T10:10:54Z DEBUG eq 2020-06-17T10:10:54Z DEBUG pres 2020-06-17T10:10:54Z DEBUG New entry: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG ipaAnchorUUID 2020-06-17T10:10:54Z DEBUG ObjectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsIndex 2020-06-17T10:10:54Z DEBUG nsSystemIndex: 2020-06-17T10:10:54Z DEBUG false 2020-06-17T10:10:54Z DEBUG only: set nsIndexType to 'eq', current value [] 2020-06-17T10:10:54Z DEBUG only: updated value ['eq'] 2020-06-17T10:10:54Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:10:54Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG ipaAnchorUUID 2020-06-17T10:10:54Z DEBUG ObjectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsIndex 2020-06-17T10:10:54Z DEBUG nsSystemIndex: 2020-06-17T10:10:54Z DEBUG false 2020-06-17T10:10:54Z DEBUG nsIndexType: 2020-06-17T10:10:54Z DEBUG eq 2020-06-17T10:10:54Z DEBUG pres 2020-06-17T10:10:54Z DEBUG Updating existing entry: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Initial value 2020-06-17T10:10:54Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG ipaAnchorUUID 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsIndex 2020-06-17T10:10:54Z DEBUG nsSystemIndex: 2020-06-17T10:10:54Z DEBUG false 2020-06-17T10:10:54Z DEBUG nsIndexType: 2020-06-17T10:10:54Z DEBUG eq 2020-06-17T10:10:54Z DEBUG pres 2020-06-17T10:10:54Z DEBUG remove: 'ipaOriginalUid' from cn, current value ['ipaAnchorUUID'] 2020-06-17T10:10:54Z DEBUG remove: 'ipaOriginalUid' not in cn 2020-06-17T10:10:54Z DEBUG --------------------------------------------- 2020-06-17T10:10:54Z DEBUG Final value after applying updates 2020-06-17T10:10:54Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:10:54Z DEBUG cn: 2020-06-17T10:10:54Z DEBUG ipaAnchorUUID 2020-06-17T10:10:54Z DEBUG objectClass: 2020-06-17T10:10:54Z DEBUG top 2020-06-17T10:10:54Z DEBUG nsIndex 2020-06-17T10:10:54Z DEBUG nsSystemIndex: 2020-06-17T10:10:54Z DEBUG false 2020-06-17T10:10:54Z DEBUG nsIndexType: 2020-06-17T10:10:54Z DEBUG eq 2020-06-17T10:10:54Z DEBUG pres 2020-06-17T10:10:54Z DEBUG [] 2020-06-17T10:10:54Z DEBUG Updated 0 2020-06-17T10:10:54Z DEBUG Done 2020-06-17T10:10:59Z DEBUG Creating task cn=indextask_138116814593112320_9318,cn=index,cn=tasks,cn=config to index attributes: ipaAnchorUUID, ipaOriginalUid 2020-06-17T10:11:00Z DEBUG Indexing finished 2020-06-17T10:11:00Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-idoverride_index.update 6.035 sec 2020-06-17T10:11:00Z DEBUG Parsing update file '/usr/share/ipa/updates/20-indices.update' 2020-06-17T10:11:00Z DEBUG New entry: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG memberuid 2020-06-17T10:11:00Z DEBUG ObjectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value [] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG memberuid 2020-06-17T10:11:00Z DEBUG ObjectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG memberHost 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG memberHost 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG memberUser 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG memberUser 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG member 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG member 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [(0, 'nsIndexType', ['pres', 'sub'])] 2020-06-17T10:11:00Z DEBUG Updated 1 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG uniquemember 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG uniquemember 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [(0, 'nsIndexType', ['sub'])] 2020-06-17T10:11:00Z DEBUG Updated 1 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG owner 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG owner 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [(0, 'nsIndexType', ['sub'])] 2020-06-17T10:11:00Z DEBUG Updated 1 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG manager 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG manager 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG secretary 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG secretary 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG seeAlso 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG seeAlso 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [(0, 'nsIndexType', ['sub'])] 2020-06-17T10:11:00Z DEBUG Updated 1 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG memberOf 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG memberOf 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG fqdn 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG fqdn 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG macAddress 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG macAddress 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG sourcehost 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG sourcehost 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG memberservice 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG memberservice 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG managedby 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG managedby 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG memberallowcmd 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG memberallowcmd 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG memberdenycmd 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG memberdenycmd 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipasudorunas 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipasudorunas 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipasudorunasgroup 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipasudorunasgroup 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG automountkey 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG add: 'pres' to nsIndexType, current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG add: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG automountkey 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=automountMapName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=automountMapName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG automountMapName 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=automountMapName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG automountMapName 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=ipaConfigString,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=ipaConfigString,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipaConfigString 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=ipaConfigString,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipaConfigString 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=ipaEnabledFlag,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=ipaEnabledFlag,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipaEnabledFlag 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=ipaEnabledFlag,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipaEnabledFlag 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=ipaKrbAuthzData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=ipaKrbAuthzData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipaKrbAuthzData 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=ipaKrbAuthzData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipaKrbAuthzData 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipakrbprincipalalias 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipakrbprincipalalias 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipauniqueid 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipauniqueid 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG New entry: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipatokenradiusconfiglink 2020-06-17T10:11:00Z DEBUG ObjectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value [] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipatokenradiusconfiglink 2020-06-17T10:11:00Z DEBUG ObjectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG New entry: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipaassignedidview 2020-06-17T10:11:00Z DEBUG ObjectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value [] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipaassignedidview 2020-06-17T10:11:00Z DEBUG ObjectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG New entry: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipaallowedtarget 2020-06-17T10:11:00Z DEBUG ObjectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value [] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipaallowedtarget 2020-06-17T10:11:00Z DEBUG ObjectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipaMemberCa 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipaMemberCa 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipaMemberCertProfile 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipaMemberCertProfile 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG userCertificate 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsSystemIndex to 'false', current value ['false'] 2020-06-17T10:11:00Z DEBUG only: updated value ['false'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG userCertificate 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ntUniqueId 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ntUniqueId 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ntUserDomainId 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ntUserDomainId 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipalocation 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipalocation 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG krbPrincipalName 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsMatchingRule: 2020-06-17T10:11:00Z DEBUG caseIgnoreIA5Match 2020-06-17T10:11:00Z DEBUG caseExactIA5Match 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsMatchingRule to 'caseIgnoreIA5Match', current value ['caseIgnoreIA5Match', 'caseExactIA5Match'] 2020-06-17T10:11:00Z DEBUG only: updated value ['caseIgnoreIA5Match'] 2020-06-17T10:11:00Z DEBUG only: set nsMatchingRule to 'caseExactIA5Match', current value ['caseIgnoreIA5Match'] 2020-06-17T10:11:00Z DEBUG only: updated value ['caseIgnoreIA5Match', 'caseExactIA5Match'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'sub'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG krbPrincipalName 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsMatchingRule: 2020-06-17T10:11:00Z DEBUG caseIgnoreIA5Match 2020-06-17T10:11:00Z DEBUG caseExactIA5Match 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG krbCanonicalName 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsSystemIndex to 'false', current value ['false'] 2020-06-17T10:11:00Z DEBUG only: updated value ['false'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'sub'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG krbCanonicalName 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG serverhostname 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG only: set nsSystemIndex to 'false', current value ['false'] 2020-06-17T10:11:00Z DEBUG only: updated value ['false'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'sub'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:00Z DEBUG only: set nsIndexType to 'sub', current value ['eq'] 2020-06-17T10:11:00Z DEBUG only: updated value ['eq', 'sub'] 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG serverhostname 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG description 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsindex 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG description 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsindex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG l 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsindex 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG l 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsindex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG nsOsVersion 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsindex 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG nsOsVersion 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsindex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG nsHardwarePlatform 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsindex 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG nsHardwarePlatform 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsindex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG nsHostLocation 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsindex 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG nsHostLocation 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG sub 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsindex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=ipServicePort,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=ipServicePort,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipServicePort 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=ipServicePort,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipServicePort 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=accessRuleType,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=accessRuleType,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG accessRuleType 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=accessRuleType,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG accessRuleType 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=hostCategory,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=hostCategory,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG hostCategory 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=hostCategory,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG hostCategory 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=idnsName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=idnsName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG idnsName 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=idnsName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG idnsName 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=ipaCertmapData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=ipaCertmapData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipaCertmapData 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=ipaCertmapData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG ipaCertmapData 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=altSecurityIdentities,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=altSecurityIdentities,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG altSecurityIdentities 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=altSecurityIdentities,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG altSecurityIdentities 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:00Z DEBUG Updating existing entry: cn=memberManager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Initial value 2020-06-17T10:11:00Z DEBUG dn: cn=memberManager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG memberManager 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG --------------------------------------------- 2020-06-17T10:11:00Z DEBUG Final value after applying updates 2020-06-17T10:11:00Z DEBUG dn: cn=memberManager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:00Z DEBUG cn: 2020-06-17T10:11:00Z DEBUG memberManager 2020-06-17T10:11:00Z DEBUG nsIndexType: 2020-06-17T10:11:00Z DEBUG eq 2020-06-17T10:11:00Z DEBUG pres 2020-06-17T10:11:00Z DEBUG nsSystemIndex: 2020-06-17T10:11:00Z DEBUG false 2020-06-17T10:11:00Z DEBUG objectClass: 2020-06-17T10:11:00Z DEBUG top 2020-06-17T10:11:00Z DEBUG nsIndex 2020-06-17T10:11:00Z DEBUG [] 2020-06-17T10:11:00Z DEBUG Updated 0 2020-06-17T10:11:00Z DEBUG Done 2020-06-17T10:11:05Z DEBUG Creating task cn=indextask_138116814655764280_9318,cn=index,cn=tasks,cn=config to index attributes: ipaallowedtarget, ipaassignedidview, ipatokenradiusconfiglink, member, memberuid, owner, seeAlso, uniquemember 2020-06-17T10:11:06Z DEBUG Indexing finished 2020-06-17T10:11:06Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-indices.update 6.267 sec 2020-06-17T10:11:06Z DEBUG Parsing update file '/usr/share/ipa/updates/20-ipaservers_hostgroup.update' 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG groupOfNames 2020-06-17T10:11:06Z DEBUG nestedGroup 2020-06-17T10:11:06Z DEBUG ipaobject 2020-06-17T10:11:06Z DEBUG ipahostgroup 2020-06-17T10:11:06Z DEBUG description: 2020-06-17T10:11:06Z DEBUG IPA server hosts 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ipaservers 2020-06-17T10:11:06Z DEBUG ipaUniqueID: 2020-06-17T10:11:06Z DEBUG 3039958c-b082-11ea-921e-525400885899 2020-06-17T10:11:06Z DEBUG member: 2020-06-17T10:11:06Z DEBUG fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG groupOfNames 2020-06-17T10:11:06Z DEBUG nestedGroup 2020-06-17T10:11:06Z DEBUG ipaobject 2020-06-17T10:11:06Z DEBUG ipahostgroup 2020-06-17T10:11:06Z DEBUG description: 2020-06-17T10:11:06Z DEBUG IPA server hosts 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ipaservers 2020-06-17T10:11:06Z DEBUG ipaUniqueID: 2020-06-17T10:11:06Z DEBUG 3039958c-b082-11ea-921e-525400885899 2020-06-17T10:11:06Z DEBUG member: 2020-06-17T10:11:06Z DEBUG fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG groupOfNames 2020-06-17T10:11:06Z DEBUG nestedGroup 2020-06-17T10:11:06Z DEBUG ipaobject 2020-06-17T10:11:06Z DEBUG ipahostgroup 2020-06-17T10:11:06Z DEBUG description: 2020-06-17T10:11:06Z DEBUG IPA server hosts 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ipaservers 2020-06-17T10:11:06Z DEBUG ipaUniqueID: 2020-06-17T10:11:06Z DEBUG 3039958c-b082-11ea-921e-525400885899 2020-06-17T10:11:06Z DEBUG member: 2020-06-17T10:11:06Z DEBUG fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG add: 'fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan' to member, current value ['fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG add: updated value ['fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG groupOfNames 2020-06-17T10:11:06Z DEBUG nestedGroup 2020-06-17T10:11:06Z DEBUG ipaobject 2020-06-17T10:11:06Z DEBUG ipahostgroup 2020-06-17T10:11:06Z DEBUG description: 2020-06-17T10:11:06Z DEBUG IPA server hosts 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ipaservers 2020-06-17T10:11:06Z DEBUG ipaUniqueID: 2020-06-17T10:11:06Z DEBUG 3039958c-b082-11ea-921e-525400885899 2020-06-17T10:11:06Z DEBUG member: 2020-06-17T10:11:06Z DEBUG fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-ipaservers_hostgroup.update 0.007 sec 2020-06-17T10:11:06Z DEBUG Parsing update file '/usr/share/ipa/updates/20-nss_ldap.update' 2020-06-17T10:11:06Z DEBUG Updating existing entry: dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG domain 2020-06-17T10:11:06Z DEBUG pilotObject 2020-06-17T10:11:06Z DEBUG dc: 2020-06-17T10:11:06Z DEBUG lin 2020-06-17T10:11:06Z DEBUG info: 2020-06-17T10:11:06Z DEBUG IPA V2.0 2020-06-17T10:11:06Z DEBUG aci: 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:06Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:06Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:11:06Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:06Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG add: 'domain' to objectClass, current value ['top', 'domain', 'pilotObject'] 2020-06-17T10:11:06Z DEBUG add: updated value ['top', 'pilotObject', 'domain'] 2020-06-17T10:11:06Z DEBUG add: 'domainRelatedObject' to objectClass, current value ['top', 'pilotObject', 'domain'] 2020-06-17T10:11:06Z DEBUG add: updated value ['top', 'pilotObject', 'domain', 'domainRelatedObject'] 2020-06-17T10:11:06Z DEBUG add: 'nisDomainObject' to objectClass, current value ['top', 'pilotObject', 'domain', 'domainRelatedObject'] 2020-06-17T10:11:06Z DEBUG add: updated value ['top', 'pilotObject', 'domain', 'domainRelatedObject', 'nisDomainObject'] 2020-06-17T10:11:06Z DEBUG add: 'lin.test.lan' to associatedDomain, current value [] 2020-06-17T10:11:06Z DEBUG add: updated value ['lin.test.lan'] 2020-06-17T10:11:06Z DEBUG add: 'lin.test.lan' to nisDomain, current value [] 2020-06-17T10:11:06Z DEBUG add: updated value ['lin.test.lan'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG pilotObject 2020-06-17T10:11:06Z DEBUG domain 2020-06-17T10:11:06Z DEBUG domainRelatedObject 2020-06-17T10:11:06Z DEBUG nisDomainObject 2020-06-17T10:11:06Z DEBUG dc: 2020-06-17T10:11:06Z DEBUG lin 2020-06-17T10:11:06Z DEBUG info: 2020-06-17T10:11:06Z DEBUG IPA V2.0 2020-06-17T10:11:06Z DEBUG aci: 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:06Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:06Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:11:06Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:06Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG associatedDomain: 2020-06-17T10:11:06Z DEBUG lin.test.lan 2020-06-17T10:11:06Z DEBUG nisDomain: 2020-06-17T10:11:06Z DEBUG lin.test.lan 2020-06-17T10:11:06Z DEBUG [(0, 'objectClass', ['domainRelatedObject', 'nisDomainObject']), (2, 'nisDomain', ['lin.test.lan']), (2, 'associatedDomain', ['lin.test.lan'])] 2020-06-17T10:11:06Z DEBUG Updated 1 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG New entry: ou=profile,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: ou=profile,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG add: 'top' to objectClass, current value [] 2020-06-17T10:11:06Z DEBUG add: updated value ['top'] 2020-06-17T10:11:06Z DEBUG add: 'organizationalUnit' to objectClass, current value ['top'] 2020-06-17T10:11:06Z DEBUG add: updated value ['top', 'organizationalUnit'] 2020-06-17T10:11:06Z DEBUG add: 'profiles' to ou, current value [] 2020-06-17T10:11:06Z DEBUG add: updated value ['profiles'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: ou=profile,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG organizationalUnit 2020-06-17T10:11:06Z DEBUG ou: 2020-06-17T10:11:06Z DEBUG profiles 2020-06-17T10:11:06Z DEBUG New entry: cn=default,ou=profile,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=default,ou=profile,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG ObjectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG DUAConfigProfile 2020-06-17T10:11:06Z DEBUG defaultServerList: 2020-06-17T10:11:06Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:11:06Z DEBUG defaultSearchBase: 2020-06-17T10:11:06Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG authenticationMethod: 2020-06-17T10:11:06Z DEBUG none 2020-06-17T10:11:06Z DEBUG searchTimeLimit: 2020-06-17T10:11:06Z DEBUG 15 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG default 2020-06-17T10:11:06Z DEBUG serviceSearchDescriptor: 2020-06-17T10:11:06Z DEBUG passwd:cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG group:cn=groups,cn=compat,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG bindTimeLimit: 2020-06-17T10:11:06Z DEBUG 5 2020-06-17T10:11:06Z DEBUG objectClassMap: 2020-06-17T10:11:06Z DEBUG shadow:shadowAccount=posixAccount 2020-06-17T10:11:06Z DEBUG followReferrals: 2020-06-17T10:11:06Z DEBUG TRUE 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=default,ou=profile,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG ObjectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG DUAConfigProfile 2020-06-17T10:11:06Z DEBUG defaultServerList: 2020-06-17T10:11:06Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:11:06Z DEBUG defaultSearchBase: 2020-06-17T10:11:06Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG authenticationMethod: 2020-06-17T10:11:06Z DEBUG none 2020-06-17T10:11:06Z DEBUG searchTimeLimit: 2020-06-17T10:11:06Z DEBUG 15 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG default 2020-06-17T10:11:06Z DEBUG serviceSearchDescriptor: 2020-06-17T10:11:06Z DEBUG passwd:cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG group:cn=groups,cn=compat,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG bindTimeLimit: 2020-06-17T10:11:06Z DEBUG 5 2020-06-17T10:11:06Z DEBUG objectClassMap: 2020-06-17T10:11:06Z DEBUG shadow:shadowAccount=posixAccount 2020-06-17T10:11:06Z DEBUG followReferrals: 2020-06-17T10:11:06Z DEBUG TRUE 2020-06-17T10:11:06Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-nss_ldap.update 0.034 sec 2020-06-17T10:11:06Z DEBUG Parsing update file '/usr/share/ipa/updates/20-replication.update' 2020-06-17T10:11:06Z DEBUG New entry: cn=replication,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=replication,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectclass: 2020-06-17T10:11:06Z DEBUG nsDS5Replica 2020-06-17T10:11:06Z DEBUG nsDS5ReplicaId: 2020-06-17T10:11:06Z DEBUG 3 2020-06-17T10:11:06Z DEBUG nsDS5ReplicaRoot: 2020-06-17T10:11:06Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=replication,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectclass: 2020-06-17T10:11:06Z DEBUG nsDS5Replica 2020-06-17T10:11:06Z DEBUG nsDS5ReplicaId: 2020-06-17T10:11:06Z DEBUG 3 2020-06-17T10:11:06Z DEBUG nsDS5ReplicaRoot: 2020-06-17T10:11:06Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG New entry: cn=replication managers,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=replication managers,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectclass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG replication managers 2020-06-17T10:11:06Z DEBUG add: 'krbprincipalname=ldap/freeipaserver.lin.test.lan@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan' to member, current value [] 2020-06-17T10:11:06Z DEBUG add: updated value ['krbprincipalname=ldap/freeipaserver.lin.test.lan@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=replication managers,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectclass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG replication managers 2020-06-17T10:11:06Z DEBUG member: 2020-06-17T10:11:06Z DEBUG krbprincipalname=ldap/freeipaserver.lin.test.lan@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG topology 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG topology 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=domain,cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=domain,cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG iparepltopoconf 2020-06-17T10:11:06Z DEBUG ipaReplTopoConfRoot: 2020-06-17T10:11:06Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG nsDS5ReplicatedAttributeList: 2020-06-17T10:11:06Z DEBUG (objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount 2020-06-17T10:11:06Z DEBUG nsDS5ReplicatedAttributeListTotal: 2020-06-17T10:11:06Z DEBUG (objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount 2020-06-17T10:11:06Z DEBUG nsds5ReplicaStripAttrs: 2020-06-17T10:11:06Z DEBUG modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG domain 2020-06-17T10:11:06Z DEBUG add: '(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount' to nsDS5ReplicatedAttributeList, current value ['(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'] 2020-06-17T10:11:06Z DEBUG add: updated value ['(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'] 2020-06-17T10:11:06Z DEBUG add: '(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount' to nsDS5ReplicatedAttributeListTotal, current value ['(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'] 2020-06-17T10:11:06Z DEBUG add: updated value ['(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'] 2020-06-17T10:11:06Z DEBUG add: 'modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp' to nsds5ReplicaStripAttrs, current value ['modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp'] 2020-06-17T10:11:06Z DEBUG add: updated value ['modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=domain,cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG iparepltopoconf 2020-06-17T10:11:06Z DEBUG ipaReplTopoConfRoot: 2020-06-17T10:11:06Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG nsDS5ReplicatedAttributeList: 2020-06-17T10:11:06Z DEBUG (objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount 2020-06-17T10:11:06Z DEBUG nsDS5ReplicatedAttributeListTotal: 2020-06-17T10:11:06Z DEBUG (objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount 2020-06-17T10:11:06Z DEBUG nsds5ReplicaStripAttrs: 2020-06-17T10:11:06Z DEBUG modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG domain 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Deleting entry cn=realm,cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG cn=realm,cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan did not exist:no such entry 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=freeipaserver.lin.test.lan,cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=freeipaserver.lin.test.lan,cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG ipaReplTopoManagedServer 2020-06-17T10:11:06Z DEBUG ipaConfigObject 2020-06-17T10:11:06Z DEBUG ipaSupportedDomainLevelConfig 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:11:06Z DEBUG ipaReplTopoManagedSuffix: 2020-06-17T10:11:06Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG ipaMinDomainLevel: 2020-06-17T10:11:06Z DEBUG 1 2020-06-17T10:11:06Z DEBUG ipaMaxDomainLevel: 2020-06-17T10:11:06Z DEBUG 1 2020-06-17T10:11:06Z DEBUG add: 'ipaReplTopoManagedServer' to objectclass, current value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig'] 2020-06-17T10:11:06Z DEBUG add: updated value ['top', 'nsContainer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig', 'ipaReplTopoManagedServer'] 2020-06-17T10:11:06Z DEBUG add: 'dc=lin,dc=test,dc=lan' to ipaReplTopoManagedSuffix, current value ['dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG add: updated value ['dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=freeipaserver.lin.test.lan,cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG ipaConfigObject 2020-06-17T10:11:06Z DEBUG ipaSupportedDomainLevelConfig 2020-06-17T10:11:06Z DEBUG ipaReplTopoManagedServer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:11:06Z DEBUG ipaReplTopoManagedSuffix: 2020-06-17T10:11:06Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG ipaMinDomainLevel: 2020-06-17T10:11:06Z DEBUG 1 2020-06-17T10:11:06Z DEBUG ipaMaxDomainLevel: 2020-06-17T10:11:06Z DEBUG 1 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=IPA Topology Configuration,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=IPA Topology Configuration,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG IPA Topology Configuration 2020-06-17T10:11:06Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-17T10:11:06Z DEBUG ldbm database 2020-06-17T10:11:06Z DEBUG Multimaster Replication Plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:06Z DEBUG ipa-topology-plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:06Z DEBUG on 2020-06-17T10:11:06Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:06Z DEBUG ipa-topology-plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:06Z DEBUG ipa_topo_init 2020-06-17T10:11:06Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:06Z DEBUG libtopology 2020-06-17T10:11:06Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:06Z DEBUG object 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:06Z DEBUG freeipa 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:06Z DEBUG 1.0 2020-06-17T10:11:06Z DEBUG nsslapd-topo-plugin-shared-binddngroup: 2020-06-17T10:11:06Z DEBUG cn=replication managers,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG nsslapd-topo-plugin-shared-config-base: 2020-06-17T10:11:06Z DEBUG cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG nsslapd-topo-plugin-shared-replica-root: 2020-06-17T10:11:06Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG o=ipaca 2020-06-17T10:11:06Z DEBUG nsslapd-topo-plugin-startup-delay: 2020-06-17T10:11:06Z DEBUG 20 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsSlapdPlugin 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=IPA Topology Configuration,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG IPA Topology Configuration 2020-06-17T10:11:06Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-17T10:11:06Z DEBUG ldbm database 2020-06-17T10:11:06Z DEBUG Multimaster Replication Plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:06Z DEBUG ipa-topology-plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:06Z DEBUG on 2020-06-17T10:11:06Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:06Z DEBUG ipa-topology-plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:06Z DEBUG ipa_topo_init 2020-06-17T10:11:06Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:06Z DEBUG libtopology 2020-06-17T10:11:06Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:06Z DEBUG object 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:06Z DEBUG freeipa 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:06Z DEBUG 1.0 2020-06-17T10:11:06Z DEBUG nsslapd-topo-plugin-shared-binddngroup: 2020-06-17T10:11:06Z DEBUG cn=replication managers,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG nsslapd-topo-plugin-shared-config-base: 2020-06-17T10:11:06Z DEBUG cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG nsslapd-topo-plugin-shared-replica-root: 2020-06-17T10:11:06Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG o=ipaca 2020-06-17T10:11:06Z DEBUG nsslapd-topo-plugin-startup-delay: 2020-06-17T10:11:06Z DEBUG 20 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsSlapdPlugin 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG New entry: cn=changelog5,cn=config 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=changelog5,cn=config 2020-06-17T10:11:06Z DEBUG addifnew: '7d' to nsslapd-changelogmaxage, current value [] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=changelog5,cn=config 2020-06-17T10:11:06Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-replication.update 0.036 sec 2020-06-17T10:11:06Z DEBUG Parsing update file '/usr/share/ipa/updates/20-sslciphers.update' 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=encryption,cn=config 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=encryption,cn=config 2020-06-17T10:11:06Z DEBUG CACertExtractFile: 2020-06-17T10:11:06Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/Self-Signed-CA.pem 2020-06-17T10:11:06Z DEBUG allowWeakCipher: 2020-06-17T10:11:06Z DEBUG off 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG encryption 2020-06-17T10:11:06Z DEBUG nsSSL3Ciphers: 2020-06-17T10:11:06Z DEBUG default 2020-06-17T10:11:06Z DEBUG nsSSLClientAuth: 2020-06-17T10:11:06Z DEBUG allowed 2020-06-17T10:11:06Z DEBUG nsSSLSessionTimeout: 2020-06-17T10:11:06Z DEBUG 0 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsEncryptionConfig 2020-06-17T10:11:06Z DEBUG nsSSLSupportedCiphers: 2020-06-17T10:11:06Z DEBUG TLS_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-17T10:11:06Z DEBUG TLS_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2020-06-17T10:11:06Z DEBUG TLS_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_ECDH_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-17T10:11:06Z DEBUG TLS_ECDH_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-17T10:11:06Z DEBUG TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-17T10:11:06Z DEBUG TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-17T10:11:06Z DEBUG TLS_ECDH_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_ECDH_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_SEED_CBC_SHA::SEED::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_RC4_128_MD5::RC4::MD5::128 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_DES_CBC_SHA::DES::SHA1::64 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_RSA_WITH_NULL_SHA::NULL::SHA1::0 2020-06-17T10:11:06Z DEBUG TLS_ECDH_RSA_WITH_NULL_SHA::NULL::SHA1::0 2020-06-17T10:11:06Z DEBUG TLS_ECDH_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_NULL_SHA::NULL::SHA1::0 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_NULL_SHA256::NULL::SHA256::0 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_NULL_MD5::NULL::MD5::0 2020-06-17T10:11:06Z DEBUG only: set nsSSL3Ciphers to 'default', current value ['default'] 2020-06-17T10:11:06Z DEBUG only: updated value ['default'] 2020-06-17T10:11:06Z DEBUG addifnew: 'off' to allowWeakCipher, current value ['off'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=encryption,cn=config 2020-06-17T10:11:06Z DEBUG CACertExtractFile: 2020-06-17T10:11:06Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/Self-Signed-CA.pem 2020-06-17T10:11:06Z DEBUG allowWeakCipher: 2020-06-17T10:11:06Z DEBUG off 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG encryption 2020-06-17T10:11:06Z DEBUG nsSSL3Ciphers: 2020-06-17T10:11:06Z DEBUG default 2020-06-17T10:11:06Z DEBUG nsSSLClientAuth: 2020-06-17T10:11:06Z DEBUG allowed 2020-06-17T10:11:06Z DEBUG nsSSLSessionTimeout: 2020-06-17T10:11:06Z DEBUG 0 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsEncryptionConfig 2020-06-17T10:11:06Z DEBUG nsSSLSupportedCiphers: 2020-06-17T10:11:06Z DEBUG TLS_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-17T10:11:06Z DEBUG TLS_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2020-06-17T10:11:06Z DEBUG TLS_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_ECDH_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-17T10:11:06Z DEBUG TLS_ECDH_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-17T10:11:06Z DEBUG TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-17T10:11:06Z DEBUG TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-17T10:11:06Z DEBUG TLS_ECDH_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_ECDH_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_SEED_CBC_SHA::SEED::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_RC4_128_MD5::RC4::MD5::128 2020-06-17T10:11:06Z DEBUG TLS_DHE_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2020-06-17T10:11:06Z DEBUG TLS_DHE_DSS_WITH_DES_CBC_SHA::DES::SHA1::64 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2020-06-17T10:11:06Z DEBUG TLS_ECDHE_RSA_WITH_NULL_SHA::NULL::SHA1::0 2020-06-17T10:11:06Z DEBUG TLS_ECDH_RSA_WITH_NULL_SHA::NULL::SHA1::0 2020-06-17T10:11:06Z DEBUG TLS_ECDH_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_NULL_SHA::NULL::SHA1::0 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_NULL_SHA256::NULL::SHA256::0 2020-06-17T10:11:06Z DEBUG TLS_RSA_WITH_NULL_MD5::NULL::MD5::0 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-sslciphers.update 0.012 sec 2020-06-17T10:11:06Z DEBUG Parsing update file '/usr/share/ipa/updates/20-syncrepl.update' 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=Retro Changelog Plugin,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=Retro Changelog Plugin,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Retro Changelog Plugin 2020-06-17T10:11:06Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-17T10:11:06Z DEBUG Class of Service 2020-06-17T10:11:06Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:06Z DEBUG database 2020-06-17T10:11:06Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:06Z DEBUG none 2020-06-17T10:11:06Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:06Z DEBUG off 2020-06-17T10:11:06Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:06Z DEBUG none 2020-06-17T10:11:06Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:06Z DEBUG retrocl_plugin_init 2020-06-17T10:11:06Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:06Z DEBUG libretrocl-plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:06Z DEBUG object 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:06Z DEBUG none 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:06Z DEBUG none 2020-06-17T10:11:06Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:11:06Z DEBUG on 2020-06-17T10:11:06Z DEBUG nsslapd-pluginprecedence: 2020-06-17T10:11:06Z DEBUG 25 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsSlapdPlugin 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG only: set nsslapd-pluginEnabled to 'on', current value ['off'] 2020-06-17T10:11:06Z DEBUG only: updated value ['on'] 2020-06-17T10:11:06Z DEBUG add: 'nsuniqueid:targetUniqueId' to nsslapd-attribute, current value [] 2020-06-17T10:11:06Z DEBUG add: updated value ['nsuniqueid:targetUniqueId'] 2020-06-17T10:11:06Z DEBUG add: '2d' to nsslapd-changelogmaxage, current value [] 2020-06-17T10:11:06Z DEBUG add: updated value ['2d'] 2020-06-17T10:11:06Z DEBUG add: 'cn=dns,dc=lin,dc=test,dc=lan' to nsslapd-include-suffix, current value [] 2020-06-17T10:11:06Z DEBUG add: updated value ['cn=dns,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=Retro Changelog Plugin,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Retro Changelog Plugin 2020-06-17T10:11:06Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-17T10:11:06Z DEBUG Class of Service 2020-06-17T10:11:06Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:06Z DEBUG database 2020-06-17T10:11:06Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:06Z DEBUG none 2020-06-17T10:11:06Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:06Z DEBUG on 2020-06-17T10:11:06Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:06Z DEBUG none 2020-06-17T10:11:06Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:06Z DEBUG retrocl_plugin_init 2020-06-17T10:11:06Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:06Z DEBUG libretrocl-plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:06Z DEBUG object 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:06Z DEBUG none 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:06Z DEBUG none 2020-06-17T10:11:06Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:11:06Z DEBUG on 2020-06-17T10:11:06Z DEBUG nsslapd-pluginprecedence: 2020-06-17T10:11:06Z DEBUG 25 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsSlapdPlugin 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG nsslapd-attribute: 2020-06-17T10:11:06Z DEBUG nsuniqueid:targetUniqueId 2020-06-17T10:11:06Z DEBUG nsslapd-changelogmaxage: 2020-06-17T10:11:06Z DEBUG 2d 2020-06-17T10:11:06Z DEBUG nsslapd-include-suffix: 2020-06-17T10:11:06Z DEBUG cn=dns,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG [(2, 'nsslapd-include-suffix', ['cn=dns,dc=lin,dc=test,dc=lan']), (2, 'nsslapd-attribute', ['nsuniqueid:targetUniqueId']), (2, 'nsslapd-changelogmaxage', ['2d']), (2, 'nsslapd-pluginEnabled', ['on'])] 2020-06-17T10:11:06Z DEBUG Updated 1 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=MemberOf Plugin,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG MemberOf Plugin 2020-06-17T10:11:06Z DEBUG memberofattr: 2020-06-17T10:11:06Z DEBUG memberOf 2020-06-17T10:11:06Z DEBUG memberofgroupattr: 2020-06-17T10:11:06Z DEBUG member 2020-06-17T10:11:06Z DEBUG memberUser 2020-06-17T10:11:06Z DEBUG memberHost 2020-06-17T10:11:06Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:06Z DEBUG database 2020-06-17T10:11:06Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:06Z DEBUG memberof plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:06Z DEBUG on 2020-06-17T10:11:06Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:06Z DEBUG memberof 2020-06-17T10:11:06Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:06Z DEBUG memberof_postop_init 2020-06-17T10:11:06Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:06Z DEBUG libmemberof-plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:06Z DEBUG betxnpostoperation 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:06Z DEBUG 389 Project 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:06Z DEBUG 1.4.2.4 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsSlapdPlugin 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG add: 'dc=lin,dc=test,dc=lan' to memberofentryscope, current value [] 2020-06-17T10:11:06Z DEBUG add: updated value ['dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG add: 'cn=compat,dc=lin,dc=test,dc=lan' to memberofentryscopeexcludesubtree, current value [] 2020-06-17T10:11:06Z DEBUG add: updated value ['cn=compat,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG add: 'cn=provisioning,dc=lin,dc=test,dc=lan' to memberofentryscopeexcludesubtree, current value ['cn=compat,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG add: updated value ['cn=compat,dc=lin,dc=test,dc=lan', 'cn=provisioning,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan' to memberofentryscopeexcludesubtree, current value ['cn=compat,dc=lin,dc=test,dc=lan', 'cn=provisioning,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG add: updated value ['cn=compat,dc=lin,dc=test,dc=lan', 'cn=provisioning,dc=lin,dc=test,dc=lan', 'cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG MemberOf Plugin 2020-06-17T10:11:06Z DEBUG memberofattr: 2020-06-17T10:11:06Z DEBUG memberOf 2020-06-17T10:11:06Z DEBUG memberofgroupattr: 2020-06-17T10:11:06Z DEBUG member 2020-06-17T10:11:06Z DEBUG memberUser 2020-06-17T10:11:06Z DEBUG memberHost 2020-06-17T10:11:06Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:06Z DEBUG database 2020-06-17T10:11:06Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:06Z DEBUG memberof plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:06Z DEBUG on 2020-06-17T10:11:06Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:06Z DEBUG memberof 2020-06-17T10:11:06Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:06Z DEBUG memberof_postop_init 2020-06-17T10:11:06Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:06Z DEBUG libmemberof-plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:06Z DEBUG betxnpostoperation 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:06Z DEBUG 389 Project 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:06Z DEBUG 1.4.2.4 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsSlapdPlugin 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG memberofentryscope: 2020-06-17T10:11:06Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG memberofentryscopeexcludesubtree: 2020-06-17T10:11:06Z DEBUG cn=compat,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG [(2, 'memberofentryscope', ['dc=lin,dc=test,dc=lan']), (2, 'memberofentryscopeexcludesubtree', ['cn=compat,dc=lin,dc=test,dc=lan', 'cn=provisioning,dc=lin,dc=test,dc=lan', 'cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:11:06Z DEBUG Updated 1 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=referential integrity postoperation,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG referential integrity postoperation 2020-06-17T10:11:06Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:06Z DEBUG database 2020-06-17T10:11:06Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:06Z DEBUG referential integrity plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:06Z DEBUG on 2020-06-17T10:11:06Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:06Z DEBUG referint 2020-06-17T10:11:06Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:06Z DEBUG referint_postop_init 2020-06-17T10:11:06Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:06Z DEBUG libreferint-plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:06Z DEBUG betxnpostoperation 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:06Z DEBUG 389 Project 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:06Z DEBUG 1.4.2.4 2020-06-17T10:11:06Z DEBUG nsslapd-pluginprecedence: 2020-06-17T10:11:06Z DEBUG 40 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsSlapdPlugin 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG referint-logfile: 2020-06-17T10:11:06Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/referint 2020-06-17T10:11:06Z DEBUG referint-membership-attr: 2020-06-17T10:11:06Z DEBUG member 2020-06-17T10:11:06Z DEBUG uniquemember 2020-06-17T10:11:06Z DEBUG owner 2020-06-17T10:11:06Z DEBUG seeAlso 2020-06-17T10:11:06Z DEBUG referint-update-delay: 2020-06-17T10:11:06Z DEBUG 0 2020-06-17T10:11:06Z DEBUG add: 'dc=lin,dc=test,dc=lan' to nsslapd-plugincontainerscope, current value [] 2020-06-17T10:11:06Z DEBUG add: updated value ['dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG add: 'dc=lin,dc=test,dc=lan' to nsslapd-pluginentryscope, current value [] 2020-06-17T10:11:06Z DEBUG add: updated value ['dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG add: 'cn=provisioning,dc=lin,dc=test,dc=lan' to nsslapd-pluginExcludeEntryScope, current value [] 2020-06-17T10:11:06Z DEBUG add: updated value ['cn=provisioning,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG referential integrity postoperation 2020-06-17T10:11:06Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:06Z DEBUG database 2020-06-17T10:11:06Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:06Z DEBUG referential integrity plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:06Z DEBUG on 2020-06-17T10:11:06Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:06Z DEBUG referint 2020-06-17T10:11:06Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:06Z DEBUG referint_postop_init 2020-06-17T10:11:06Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:06Z DEBUG libreferint-plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:06Z DEBUG betxnpostoperation 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:06Z DEBUG 389 Project 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:06Z DEBUG 1.4.2.4 2020-06-17T10:11:06Z DEBUG nsslapd-pluginprecedence: 2020-06-17T10:11:06Z DEBUG 40 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsSlapdPlugin 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG referint-logfile: 2020-06-17T10:11:06Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/referint 2020-06-17T10:11:06Z DEBUG referint-membership-attr: 2020-06-17T10:11:06Z DEBUG member 2020-06-17T10:11:06Z DEBUG uniquemember 2020-06-17T10:11:06Z DEBUG owner 2020-06-17T10:11:06Z DEBUG seeAlso 2020-06-17T10:11:06Z DEBUG referint-update-delay: 2020-06-17T10:11:06Z DEBUG 0 2020-06-17T10:11:06Z DEBUG nsslapd-plugincontainerscope: 2020-06-17T10:11:06Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG nsslapd-pluginentryscope: 2020-06-17T10:11:06Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG nsslapd-pluginExcludeEntryScope: 2020-06-17T10:11:06Z DEBUG cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG [(2, 'nsslapd-pluginentryscope', ['dc=lin,dc=test,dc=lan']), (2, 'nsslapd-pluginExcludeEntryScope', ['cn=provisioning,dc=lin,dc=test,dc=lan']), (2, 'nsslapd-plugincontainerscope', ['dc=lin,dc=test,dc=lan'])] 2020-06-17T10:11:06Z DEBUG Updated 1 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=Content Synchronization,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=Content Synchronization,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Content Synchronization 2020-06-17T10:11:06Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-17T10:11:06Z DEBUG Retro Changelog Plugin 2020-06-17T10:11:06Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:06Z DEBUG database 2020-06-17T10:11:06Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:06Z DEBUG none 2020-06-17T10:11:06Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:06Z DEBUG off 2020-06-17T10:11:06Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:06Z DEBUG none 2020-06-17T10:11:06Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:06Z DEBUG sync_init 2020-06-17T10:11:06Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:06Z DEBUG libcontentsync-plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:06Z DEBUG object 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:06Z DEBUG none 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:06Z DEBUG none 2020-06-17T10:11:06Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:11:06Z DEBUG on 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsSlapdPlugin 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG only: set nsslapd-pluginEnabled to 'on', current value ['off'] 2020-06-17T10:11:06Z DEBUG only: updated value ['on'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=Content Synchronization,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Content Synchronization 2020-06-17T10:11:06Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-17T10:11:06Z DEBUG Retro Changelog Plugin 2020-06-17T10:11:06Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:06Z DEBUG database 2020-06-17T10:11:06Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:06Z DEBUG none 2020-06-17T10:11:06Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:06Z DEBUG on 2020-06-17T10:11:06Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:06Z DEBUG none 2020-06-17T10:11:06Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:06Z DEBUG sync_init 2020-06-17T10:11:06Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:06Z DEBUG libcontentsync-plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:06Z DEBUG object 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:06Z DEBUG none 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:06Z DEBUG none 2020-06-17T10:11:06Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:11:06Z DEBUG on 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsSlapdPlugin 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG [(2, 'nsslapd-pluginEnabled', ['on'])] 2020-06-17T10:11:06Z DEBUG Updated 1 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG IPA Unique IDs 2020-06-17T10:11:06Z DEBUG ipauuidattr: 2020-06-17T10:11:06Z DEBUG ipaUniqueID 2020-06-17T10:11:06Z DEBUG ipauuidenforce: 2020-06-17T10:11:06Z DEBUG TRUE 2020-06-17T10:11:06Z DEBUG ipauuidfilter: 2020-06-17T10:11:06Z DEBUG (|(objectclass=ipaObject)(objectclass=ipaAssociation)) 2020-06-17T10:11:06Z DEBUG ipauuidmagicregen: 2020-06-17T10:11:06Z DEBUG autogenerate 2020-06-17T10:11:06Z DEBUG ipauuidscope: 2020-06-17T10:11:06Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG add: 'cn=provisioning,dc=lin,dc=test,dc=lan' to ipaUuidExcludeSubtree, current value [] 2020-06-17T10:11:06Z DEBUG add: updated value ['cn=provisioning,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG IPA Unique IDs 2020-06-17T10:11:06Z DEBUG ipauuidattr: 2020-06-17T10:11:06Z DEBUG ipaUniqueID 2020-06-17T10:11:06Z DEBUG ipauuidenforce: 2020-06-17T10:11:06Z DEBUG TRUE 2020-06-17T10:11:06Z DEBUG ipauuidfilter: 2020-06-17T10:11:06Z DEBUG (|(objectclass=ipaObject)(objectclass=ipaAssociation)) 2020-06-17T10:11:06Z DEBUG ipauuidmagicregen: 2020-06-17T10:11:06Z DEBUG autogenerate 2020-06-17T10:11:06Z DEBUG ipauuidscope: 2020-06-17T10:11:06Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG ipaUuidExcludeSubtree: 2020-06-17T10:11:06Z DEBUG cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG [(2, 'ipaUuidExcludeSubtree', ['cn=provisioning,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:11:06Z DEBUG Updated 1 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-syncrepl.update 0.060 sec 2020-06-17T10:11:06Z DEBUG Parsing update file '/usr/share/ipa/updates/20-user_private_groups.update' 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG mepTemplateEntry 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG UPG Template 2020-06-17T10:11:06Z DEBUG mepRDNAttr: 2020-06-17T10:11:06Z DEBUG cn 2020-06-17T10:11:06Z DEBUG mepStaticAttr: 2020-06-17T10:11:06Z DEBUG objectclass: posixgroup 2020-06-17T10:11:06Z DEBUG objectclass: ipaobject 2020-06-17T10:11:06Z DEBUG ipaUniqueId: autogenerate 2020-06-17T10:11:06Z DEBUG mepMappedAttr: 2020-06-17T10:11:06Z DEBUG cn: $uid 2020-06-17T10:11:06Z DEBUG gidNumber: $uidNumber 2020-06-17T10:11:06Z DEBUG description: User private group for $uid 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG mepTemplateEntry 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG UPG Template 2020-06-17T10:11:06Z DEBUG mepRDNAttr: 2020-06-17T10:11:06Z DEBUG cn 2020-06-17T10:11:06Z DEBUG mepStaticAttr: 2020-06-17T10:11:06Z DEBUG objectclass: posixgroup 2020-06-17T10:11:06Z DEBUG objectclass: ipaobject 2020-06-17T10:11:06Z DEBUG ipaUniqueId: autogenerate 2020-06-17T10:11:06Z DEBUG mepMappedAttr: 2020-06-17T10:11:06Z DEBUG cn: $uid 2020-06-17T10:11:06Z DEBUG gidNumber: $uidNumber 2020-06-17T10:11:06Z DEBUG description: User private group for $uid 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG UPG Definition 2020-06-17T10:11:06Z DEBUG originScope: 2020-06-17T10:11:06Z DEBUG cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG originFilter: 2020-06-17T10:11:06Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2020-06-17T10:11:06Z DEBUG managedBase: 2020-06-17T10:11:06Z DEBUG cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG managedTemplate: 2020-06-17T10:11:06Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG UPG Definition 2020-06-17T10:11:06Z DEBUG originScope: 2020-06-17T10:11:06Z DEBUG cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG originFilter: 2020-06-17T10:11:06Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2020-06-17T10:11:06Z DEBUG managedBase: 2020-06-17T10:11:06Z DEBUG cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG managedTemplate: 2020-06-17T10:11:06Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG UPG Definition 2020-06-17T10:11:06Z DEBUG originScope: 2020-06-17T10:11:06Z DEBUG cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG originFilter: 2020-06-17T10:11:06Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2020-06-17T10:11:06Z DEBUG managedBase: 2020-06-17T10:11:06Z DEBUG cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG managedTemplate: 2020-06-17T10:11:06Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG replace: objectclass=posixAccount not found, skipping 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG UPG Definition 2020-06-17T10:11:06Z DEBUG originScope: 2020-06-17T10:11:06Z DEBUG cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG originFilter: 2020-06-17T10:11:06Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2020-06-17T10:11:06Z DEBUG managedBase: 2020-06-17T10:11:06Z DEBUG cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG managedTemplate: 2020-06-17T10:11:06Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-user_private_groups.update 0.009 sec 2020-06-17T10:11:06Z DEBUG Parsing update file '/usr/share/ipa/updates/20-uuid.update' 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG IPK11 Unique IDs 2020-06-17T10:11:06Z DEBUG ipauuidattr: 2020-06-17T10:11:06Z DEBUG ipk11UniqueID 2020-06-17T10:11:06Z DEBUG ipauuidenforce: 2020-06-17T10:11:06Z DEBUG FALSE 2020-06-17T10:11:06Z DEBUG ipauuidfilter: 2020-06-17T10:11:06Z DEBUG (objectclass=ipk11Object) 2020-06-17T10:11:06Z DEBUG ipauuidmagicregen: 2020-06-17T10:11:06Z DEBUG autogenerate 2020-06-17T10:11:06Z DEBUG ipauuidscope: 2020-06-17T10:11:06Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG IPK11 Unique IDs 2020-06-17T10:11:06Z DEBUG ipauuidattr: 2020-06-17T10:11:06Z DEBUG ipk11UniqueID 2020-06-17T10:11:06Z DEBUG ipauuidenforce: 2020-06-17T10:11:06Z DEBUG FALSE 2020-06-17T10:11:06Z DEBUG ipauuidfilter: 2020-06-17T10:11:06Z DEBUG (objectclass=ipk11Object) 2020-06-17T10:11:06Z DEBUG ipauuidmagicregen: 2020-06-17T10:11:06Z DEBUG autogenerate 2020-06-17T10:11:06Z DEBUG ipauuidscope: 2020-06-17T10:11:06Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-uuid.update 0.003 sec 2020-06-17T10:11:06Z DEBUG Parsing update file '/usr/share/ipa/updates/20-whoami.update' 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=whoami,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG whoami 2020-06-17T10:11:06Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:06Z DEBUG database 2020-06-17T10:11:06Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:06Z DEBUG whoami extended operation plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:06Z DEBUG on 2020-06-17T10:11:06Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:06Z DEBUG whoami-plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:06Z DEBUG whoami_init 2020-06-17T10:11:06Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:06Z DEBUG libwhoami-plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:06Z DEBUG extendedop 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:06Z DEBUG 389 Project 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:06Z DEBUG 1.4.2.4 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsSlapdPlugin 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG whoami 2020-06-17T10:11:06Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:06Z DEBUG database 2020-06-17T10:11:06Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:06Z DEBUG whoami extended operation plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:06Z DEBUG on 2020-06-17T10:11:06Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:06Z DEBUG whoami-plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:06Z DEBUG whoami_init 2020-06-17T10:11:06Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:06Z DEBUG libwhoami-plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:06Z DEBUG extendedop 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:06Z DEBUG 389 Project 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:06Z DEBUG 1.4.2.4 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsSlapdPlugin 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-whoami.update 0.005 sec 2020-06-17T10:11:06Z DEBUG Parsing update file '/usr/share/ipa/updates/20-winsync_index.update' 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ntUniqueId 2020-06-17T10:11:06Z DEBUG nsIndexType: 2020-06-17T10:11:06Z DEBUG eq 2020-06-17T10:11:06Z DEBUG pres 2020-06-17T10:11:06Z DEBUG nsSystemIndex: 2020-06-17T10:11:06Z DEBUG false 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsIndex 2020-06-17T10:11:06Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres'] 2020-06-17T10:11:06Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:06Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:06Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ntUniqueId 2020-06-17T10:11:06Z DEBUG nsIndexType: 2020-06-17T10:11:06Z DEBUG eq 2020-06-17T10:11:06Z DEBUG pres 2020-06-17T10:11:06Z DEBUG nsSystemIndex: 2020-06-17T10:11:06Z DEBUG false 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsIndex 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ntUserDomainId 2020-06-17T10:11:06Z DEBUG nsIndexType: 2020-06-17T10:11:06Z DEBUG eq 2020-06-17T10:11:06Z DEBUG pres 2020-06-17T10:11:06Z DEBUG nsSystemIndex: 2020-06-17T10:11:06Z DEBUG false 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsIndex 2020-06-17T10:11:06Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres'] 2020-06-17T10:11:06Z DEBUG only: updated value ['eq'] 2020-06-17T10:11:06Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-17T10:11:06Z DEBUG only: updated value ['eq', 'pres'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ntUserDomainId 2020-06-17T10:11:06Z DEBUG nsIndexType: 2020-06-17T10:11:06Z DEBUG eq 2020-06-17T10:11:06Z DEBUG pres 2020-06-17T10:11:06Z DEBUG nsSystemIndex: 2020-06-17T10:11:06Z DEBUG false 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsIndex 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-winsync_index.update 0.005 sec 2020-06-17T10:11:06Z DEBUG Parsing update file '/usr/share/ipa/updates/21-ca_renewal_container.update' 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ca_renewal 2020-06-17T10:11:06Z DEBUG add: 'top' to objectClass, current value ['nsContainer', 'top'] 2020-06-17T10:11:06Z DEBUG add: updated value ['nsContainer', 'top'] 2020-06-17T10:11:06Z DEBUG add: 'nsContainer' to objectClass, current value ['nsContainer', 'top'] 2020-06-17T10:11:06Z DEBUG add: updated value ['top', 'nsContainer'] 2020-06-17T10:11:06Z DEBUG add: 'ca_renewal' to cn, current value ['ca_renewal'] 2020-06-17T10:11:06Z DEBUG add: updated value ['ca_renewal'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ca_renewal 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG LDAP update duration: /usr/share/ipa/updates/21-ca_renewal_container.update 0.002 sec 2020-06-17T10:11:06Z DEBUG Parsing update file '/usr/share/ipa/updates/21-certstore_container.update' 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=certificates,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG certificates 2020-06-17T10:11:06Z DEBUG add: 'top' to objectClass, current value ['nsContainer', 'top'] 2020-06-17T10:11:06Z DEBUG add: updated value ['nsContainer', 'top'] 2020-06-17T10:11:06Z DEBUG add: 'nsContainer' to objectClass, current value ['nsContainer', 'top'] 2020-06-17T10:11:06Z DEBUG add: updated value ['top', 'nsContainer'] 2020-06-17T10:11:06Z DEBUG add: 'certificates' to cn, current value ['certificates'] 2020-06-17T10:11:06Z DEBUG add: updated value ['certificates'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG certificates 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG LDAP update duration: /usr/share/ipa/updates/21-certstore_container.update 0.002 sec 2020-06-17T10:11:06Z DEBUG Parsing update file '/usr/share/ipa/updates/21-replicas_container.update' 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=replicas,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG replicas 2020-06-17T10:11:06Z DEBUG add: 'top' to objectClass, current value ['nsContainer', 'top'] 2020-06-17T10:11:06Z DEBUG add: updated value ['nsContainer', 'top'] 2020-06-17T10:11:06Z DEBUG add: 'nsContainer' to objectClass, current value ['nsContainer', 'top'] 2020-06-17T10:11:06Z DEBUG add: updated value ['top', 'nsContainer'] 2020-06-17T10:11:06Z DEBUG add: 'replicas' to cn, current value ['replicas'] 2020-06-17T10:11:06Z DEBUG add: updated value ['replicas'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG replicas 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG LDAP update duration: /usr/share/ipa/updates/21-replicas_container.update 0.002 sec 2020-06-17T10:11:06Z DEBUG Parsing update file '/usr/share/ipa/updates/25-referint.update' 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=referential integrity postoperation,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG referential integrity postoperation 2020-06-17T10:11:06Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:06Z DEBUG database 2020-06-17T10:11:06Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:06Z DEBUG referential integrity plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:06Z DEBUG on 2020-06-17T10:11:06Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:06Z DEBUG referint 2020-06-17T10:11:06Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:06Z DEBUG referint_postop_init 2020-06-17T10:11:06Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:06Z DEBUG libreferint-plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:06Z DEBUG betxnpostoperation 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:06Z DEBUG 389 Project 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:06Z DEBUG 1.4.2.4 2020-06-17T10:11:06Z DEBUG nsslapd-pluginprecedence: 2020-06-17T10:11:06Z DEBUG 40 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsSlapdPlugin 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG referint-logfile: 2020-06-17T10:11:06Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/referint 2020-06-17T10:11:06Z DEBUG referint-membership-attr: 2020-06-17T10:11:06Z DEBUG member 2020-06-17T10:11:06Z DEBUG uniquemember 2020-06-17T10:11:06Z DEBUG owner 2020-06-17T10:11:06Z DEBUG seeAlso 2020-06-17T10:11:06Z DEBUG referint-update-delay: 2020-06-17T10:11:06Z DEBUG 0 2020-06-17T10:11:06Z DEBUG nsslapd-pluginentryscope: 2020-06-17T10:11:06Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG nsslapd-pluginexcludeentryscope: 2020-06-17T10:11:06Z DEBUG cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG nsslapd-plugincontainerscope: 2020-06-17T10:11:06Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG add: 'manager' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso'] 2020-06-17T10:11:06Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager'] 2020-06-17T10:11:06Z DEBUG add: 'secretary' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager'] 2020-06-17T10:11:06Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary'] 2020-06-17T10:11:06Z DEBUG add: 'memberuser' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary'] 2020-06-17T10:11:06Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser'] 2020-06-17T10:11:06Z DEBUG add: 'memberhost' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser'] 2020-06-17T10:11:06Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost'] 2020-06-17T10:11:06Z DEBUG add: 'sourcehost' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost'] 2020-06-17T10:11:06Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost'] 2020-06-17T10:11:06Z DEBUG add: 'memberservice' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost'] 2020-06-17T10:11:06Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice'] 2020-06-17T10:11:06Z DEBUG add: 'managedby' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice'] 2020-06-17T10:11:06Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby'] 2020-06-17T10:11:06Z DEBUG add: 'memberallowcmd' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby'] 2020-06-17T10:11:06Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd'] 2020-06-17T10:11:06Z DEBUG add: 'memberdenycmd' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd'] 2020-06-17T10:11:06Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd'] 2020-06-17T10:11:06Z DEBUG add: 'ipasudorunas' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd'] 2020-06-17T10:11:06Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas'] 2020-06-17T10:11:06Z DEBUG add: 'ipasudorunasgroup' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas'] 2020-06-17T10:11:06Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup'] 2020-06-17T10:11:06Z DEBUG add: 'ipatokenradiusconfiglink' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup'] 2020-06-17T10:11:06Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink'] 2020-06-17T10:11:06Z DEBUG add: 'ipaassignedidview' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink'] 2020-06-17T10:11:06Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview'] 2020-06-17T10:11:06Z DEBUG add: 'ipaallowedtarget' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview'] 2020-06-17T10:11:06Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget'] 2020-06-17T10:11:06Z DEBUG add: 'ipamemberca' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget'] 2020-06-17T10:11:06Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca'] 2020-06-17T10:11:06Z DEBUG add: 'ipamembercertprofile' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca'] 2020-06-17T10:11:06Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile'] 2020-06-17T10:11:06Z DEBUG add: 'ipalocation' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile'] 2020-06-17T10:11:06Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation'] 2020-06-17T10:11:06Z DEBUG add: 'membermanager' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation'] 2020-06-17T10:11:06Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation', 'membermanager'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG referential integrity postoperation 2020-06-17T10:11:06Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:06Z DEBUG database 2020-06-17T10:11:06Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:06Z DEBUG referential integrity plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:06Z DEBUG on 2020-06-17T10:11:06Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:06Z DEBUG referint 2020-06-17T10:11:06Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:06Z DEBUG referint_postop_init 2020-06-17T10:11:06Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:06Z DEBUG libreferint-plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:06Z DEBUG betxnpostoperation 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:06Z DEBUG 389 Project 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:06Z DEBUG 1.4.2.4 2020-06-17T10:11:06Z DEBUG nsslapd-pluginprecedence: 2020-06-17T10:11:06Z DEBUG 40 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsSlapdPlugin 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG referint-logfile: 2020-06-17T10:11:06Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/referint 2020-06-17T10:11:06Z DEBUG referint-membership-attr: 2020-06-17T10:11:06Z DEBUG member 2020-06-17T10:11:06Z DEBUG uniquemember 2020-06-17T10:11:06Z DEBUG owner 2020-06-17T10:11:06Z DEBUG seeAlso 2020-06-17T10:11:06Z DEBUG manager 2020-06-17T10:11:06Z DEBUG secretary 2020-06-17T10:11:06Z DEBUG memberuser 2020-06-17T10:11:06Z DEBUG memberhost 2020-06-17T10:11:06Z DEBUG sourcehost 2020-06-17T10:11:06Z DEBUG memberservice 2020-06-17T10:11:06Z DEBUG managedby 2020-06-17T10:11:06Z DEBUG memberallowcmd 2020-06-17T10:11:06Z DEBUG memberdenycmd 2020-06-17T10:11:06Z DEBUG ipasudorunas 2020-06-17T10:11:06Z DEBUG ipasudorunasgroup 2020-06-17T10:11:06Z DEBUG ipatokenradiusconfiglink 2020-06-17T10:11:06Z DEBUG ipaassignedidview 2020-06-17T10:11:06Z DEBUG ipaallowedtarget 2020-06-17T10:11:06Z DEBUG ipamemberca 2020-06-17T10:11:06Z DEBUG ipamembercertprofile 2020-06-17T10:11:06Z DEBUG ipalocation 2020-06-17T10:11:06Z DEBUG membermanager 2020-06-17T10:11:06Z DEBUG referint-update-delay: 2020-06-17T10:11:06Z DEBUG 0 2020-06-17T10:11:06Z DEBUG nsslapd-pluginentryscope: 2020-06-17T10:11:06Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG nsslapd-pluginexcludeentryscope: 2020-06-17T10:11:06Z DEBUG cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG nsslapd-plugincontainerscope: 2020-06-17T10:11:06Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG [(0, 'referint-membership-attr', ['manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation', 'membermanager'])] 2020-06-17T10:11:06Z DEBUG Updated 1 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG LDAP update duration: /usr/share/ipa/updates/25-referint.update 0.018 sec 2020-06-17T10:11:06Z DEBUG Parsing update file '/usr/share/ipa/updates/30-ipservices.update' 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=ipservices,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=ipservices,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ipservices 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=ipservices,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ipservices 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG LDAP update duration: /usr/share/ipa/updates/30-ipservices.update 0.002 sec 2020-06-17T10:11:06Z DEBUG Parsing update file '/usr/share/ipa/updates/30-provisioning.update' 2020-06-17T10:11:06Z DEBUG New entry: cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectclass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG provisioning 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectclass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG provisioning 2020-06-17T10:11:06Z DEBUG New entry: cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectclass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG accounts 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectclass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG accounts 2020-06-17T10:11:06Z DEBUG New entry: cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectclass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG staged users 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectclass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG staged users 2020-06-17T10:11:06Z DEBUG New entry: cn=deleted users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectclass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG deleted users 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectclass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG deleted users 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG staged users 2020-06-17T10:11:06Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=lin,dc=test,dc=lan";)' from aci, current value [] 2020-06-17T10:11:06Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:11:06Z DEBUG add: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value [] 2020-06-17T10:11:06Z DEBUG add: updated value ['(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG staged users 2020-06-17T10:11:06Z DEBUG aci: 2020-06-17T10:11:06Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG [(2, 'aci', ['(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:11:06Z DEBUG Updated 1 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=deleted users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG deleted users 2020-06-17T10:11:06Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=lin,dc=test,dc=lan";)' from aci, current value [] 2020-06-17T10:11:06Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:11:06Z DEBUG add: '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value [] 2020-06-17T10:11:06Z DEBUG add: updated value ['(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:06Z DEBUG add: '(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)' to aci, current value ['(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:06Z DEBUG add: updated value ['(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG deleted users 2020-06-17T10:11:06Z DEBUG aci: 2020-06-17T10:11:06Z DEBUG (targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";) 2020-06-17T10:11:06Z DEBUG [(2, 'aci', ['(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)'])] 2020-06-17T10:11:06Z DEBUG Updated 1 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG New entry: cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cosSuperDefinition 2020-06-17T10:11:06Z DEBUG cosPointerDefinition 2020-06-17T10:11:06Z DEBUG ldapSubEntry 2020-06-17T10:11:06Z DEBUG costemplatedn: 2020-06-17T10:11:06Z DEBUG cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG cosAttribute: 2020-06-17T10:11:06Z DEBUG nsaccountlock operational 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG provisioning accounts lock 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cosSuperDefinition 2020-06-17T10:11:06Z DEBUG cosPointerDefinition 2020-06-17T10:11:06Z DEBUG ldapSubEntry 2020-06-17T10:11:06Z DEBUG costemplatedn: 2020-06-17T10:11:06Z DEBUG cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG cosAttribute: 2020-06-17T10:11:06Z DEBUG nsaccountlock operational 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG provisioning accounts lock 2020-06-17T10:11:06Z DEBUG New entry: cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG cosTemplate 2020-06-17T10:11:06Z DEBUG cosPriority: 2020-06-17T10:11:06Z DEBUG 1 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Inactivation cos template 2020-06-17T10:11:06Z DEBUG nsAccountLock: 2020-06-17T10:11:06Z DEBUG true 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG cosTemplate 2020-06-17T10:11:06Z DEBUG cosPriority: 2020-06-17T10:11:06Z DEBUG 1 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Inactivation cos template 2020-06-17T10:11:06Z DEBUG nsAccountLock: 2020-06-17T10:11:06Z DEBUG true 2020-06-17T10:11:06Z DEBUG LDAP update duration: /usr/share/ipa/updates/30-provisioning.update 0.047 sec 2020-06-17T10:11:06Z DEBUG Parsing update file '/usr/share/ipa/updates/30-s4u2proxy.update' 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG s4u2proxy 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG s4u2proxy 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG ipaKrb5DelegationACL 2020-06-17T10:11:06Z DEBUG groupOfPrincipals 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ipa-http-delegation 2020-06-17T10:11:06Z DEBUG memberPrincipal: 2020-06-17T10:11:06Z DEBUG HTTP/freeipaserver.lin.test.lan@LIN.TEST.LAN 2020-06-17T10:11:06Z DEBUG ipaAllowedTarget: 2020-06-17T10:11:06Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG ipaKrb5DelegationACL 2020-06-17T10:11:06Z DEBUG groupOfPrincipals 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ipa-http-delegation 2020-06-17T10:11:06Z DEBUG memberPrincipal: 2020-06-17T10:11:06Z DEBUG HTTP/freeipaserver.lin.test.lan@LIN.TEST.LAN 2020-06-17T10:11:06Z DEBUG ipaAllowedTarget: 2020-06-17T10:11:06Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG groupOfPrincipals 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ipa-ldap-delegation-targets 2020-06-17T10:11:06Z DEBUG memberPrincipal: 2020-06-17T10:11:06Z DEBUG ldap/freeipaserver.lin.test.lan@LIN.TEST.LAN 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG groupOfPrincipals 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ipa-ldap-delegation-targets 2020-06-17T10:11:06Z DEBUG memberPrincipal: 2020-06-17T10:11:06Z DEBUG ldap/freeipaserver.lin.test.lan@LIN.TEST.LAN 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG ipaKrb5DelegationACL 2020-06-17T10:11:06Z DEBUG groupOfPrincipals 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ipa-http-delegation 2020-06-17T10:11:06Z DEBUG memberPrincipal: 2020-06-17T10:11:06Z DEBUG HTTP/freeipaserver.lin.test.lan@LIN.TEST.LAN 2020-06-17T10:11:06Z DEBUG ipaAllowedTarget: 2020-06-17T10:11:06Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG add: 'HTTP/freeipaserver.lin.test.lan@LIN.TEST.LAN' to memberPrincipal, current value ['HTTP/freeipaserver.lin.test.lan@LIN.TEST.LAN'] 2020-06-17T10:11:06Z DEBUG add: updated value ['HTTP/freeipaserver.lin.test.lan@LIN.TEST.LAN'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG ipaKrb5DelegationACL 2020-06-17T10:11:06Z DEBUG groupOfPrincipals 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ipa-http-delegation 2020-06-17T10:11:06Z DEBUG memberPrincipal: 2020-06-17T10:11:06Z DEBUG HTTP/freeipaserver.lin.test.lan@LIN.TEST.LAN 2020-06-17T10:11:06Z DEBUG ipaAllowedTarget: 2020-06-17T10:11:06Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG groupOfPrincipals 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ipa-ldap-delegation-targets 2020-06-17T10:11:06Z DEBUG memberPrincipal: 2020-06-17T10:11:06Z DEBUG ldap/freeipaserver.lin.test.lan@LIN.TEST.LAN 2020-06-17T10:11:06Z DEBUG add: 'ldap/freeipaserver.lin.test.lan@LIN.TEST.LAN' to memberPrincipal, current value ['ldap/freeipaserver.lin.test.lan@LIN.TEST.LAN'] 2020-06-17T10:11:06Z DEBUG add: updated value ['ldap/freeipaserver.lin.test.lan@LIN.TEST.LAN'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG groupOfPrincipals 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ipa-ldap-delegation-targets 2020-06-17T10:11:06Z DEBUG memberPrincipal: 2020-06-17T10:11:06Z DEBUG ldap/freeipaserver.lin.test.lan@LIN.TEST.LAN 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG LDAP update duration: /usr/share/ipa/updates/30-s4u2proxy.update 0.013 sec 2020-06-17T10:11:06Z DEBUG Parsing update file '/usr/share/ipa/updates/37-locations.update' 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=locations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=locations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG locations 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=locations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG locations 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG LDAP update duration: /usr/share/ipa/updates/37-locations.update 0.002 sec 2020-06-17T10:11:06Z DEBUG Parsing update file '/usr/share/ipa/updates/40-automember.update' 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=Auto Membership Plugin,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG automemberprocessmodifyops: 2020-06-17T10:11:06Z DEBUG on 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Auto Membership Plugin 2020-06-17T10:11:06Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:06Z DEBUG database 2020-06-17T10:11:06Z DEBUG nsslapd-pluginConfigArea: 2020-06-17T10:11:06Z DEBUG cn=automember,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:06Z DEBUG Auto Membership plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:06Z DEBUG on 2020-06-17T10:11:06Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:06Z DEBUG Auto Membership 2020-06-17T10:11:06Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:06Z DEBUG automember_init 2020-06-17T10:11:06Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:06Z DEBUG libautomember-plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:06Z DEBUG betxnpreoperation 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:06Z DEBUG 389 Project 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:06Z DEBUG 1.4.2.4 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsSlapdPlugin 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG addifnew: 'cn=automember,cn=etc,dc=lin,dc=test,dc=lan' to nsslapd-pluginConfigArea, current value ['cn=automember,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2020-06-17T10:11:06Z DEBUG automemberprocessmodifyops: 2020-06-17T10:11:06Z DEBUG on 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Auto Membership Plugin 2020-06-17T10:11:06Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:06Z DEBUG database 2020-06-17T10:11:06Z DEBUG nsslapd-pluginConfigArea: 2020-06-17T10:11:06Z DEBUG cn=automember,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:06Z DEBUG Auto Membership plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:06Z DEBUG on 2020-06-17T10:11:06Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:06Z DEBUG Auto Membership 2020-06-17T10:11:06Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:06Z DEBUG automember_init 2020-06-17T10:11:06Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:06Z DEBUG libautomember-plugin 2020-06-17T10:11:06Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:06Z DEBUG betxnpreoperation 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:06Z DEBUG 389 Project 2020-06-17T10:11:06Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:06Z DEBUG 1.4.2.4 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsSlapdPlugin 2020-06-17T10:11:06Z DEBUG extensibleObject 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=automember,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=automember,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG automember 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=automember,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG automember 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=Hostgroup,cn=automember,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=Hostgroup,cn=automember,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG autoMemberDefinition 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Hostgroup 2020-06-17T10:11:06Z DEBUG autoMemberScope: 2020-06-17T10:11:06Z DEBUG cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG autoMemberFilter: 2020-06-17T10:11:06Z DEBUG objectclass=ipaHost 2020-06-17T10:11:06Z DEBUG autoMemberGroupingAttr: 2020-06-17T10:11:06Z DEBUG member:dn 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=Hostgroup,cn=automember,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG autoMemberDefinition 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Hostgroup 2020-06-17T10:11:06Z DEBUG autoMemberScope: 2020-06-17T10:11:06Z DEBUG cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG autoMemberFilter: 2020-06-17T10:11:06Z DEBUG objectclass=ipaHost 2020-06-17T10:11:06Z DEBUG autoMemberGroupingAttr: 2020-06-17T10:11:06Z DEBUG member:dn 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=Group,cn=automember,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=Group,cn=automember,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG autoMemberDefinition 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Group 2020-06-17T10:11:06Z DEBUG autoMemberScope: 2020-06-17T10:11:06Z DEBUG cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG autoMemberFilter: 2020-06-17T10:11:06Z DEBUG objectclass=posixAccount 2020-06-17T10:11:06Z DEBUG autoMemberGroupingAttr: 2020-06-17T10:11:06Z DEBUG member:dn 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=Group,cn=automember,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG autoMemberDefinition 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Group 2020-06-17T10:11:06Z DEBUG autoMemberScope: 2020-06-17T10:11:06Z DEBUG cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG autoMemberFilter: 2020-06-17T10:11:06Z DEBUG objectclass=posixAccount 2020-06-17T10:11:06Z DEBUG autoMemberGroupingAttr: 2020-06-17T10:11:06Z DEBUG member:dn 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-automember.update 0.012 sec 2020-06-17T10:11:06Z DEBUG Parsing update file '/usr/share/ipa/updates/40-certprofile.update' 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ca 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ca 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=certprofiles,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=certprofiles,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG certprofiles 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=certprofiles,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG certprofiles 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-certprofile.update 0.004 sec 2020-06-17T10:11:06Z DEBUG Parsing update file '/usr/share/ipa/updates/40-delegation.update' 2020-06-17T10:11:06Z DEBUG New entry: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG nestedgroup 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Write IPA Configuration 2020-06-17T10:11:06Z DEBUG description: 2020-06-17T10:11:06Z DEBUG Write IPA Configuration 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG nestedgroup 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Write IPA Configuration 2020-06-17T10:11:06Z DEBUG description: 2020-06-17T10:11:06Z DEBUG Write IPA Configuration 2020-06-17T10:11:06Z DEBUG New entry: cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG ipapermission 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Write IPA Configuration 2020-06-17T10:11:06Z DEBUG member: 2020-06-17T10:11:06Z DEBUG cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG ipapermission 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Write IPA Configuration 2020-06-17T10:11:06Z DEBUG member: 2020-06-17T10:11:06Z DEBUG cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG Updating existing entry: dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG domain 2020-06-17T10:11:06Z DEBUG pilotObject 2020-06-17T10:11:06Z DEBUG domainRelatedObject 2020-06-17T10:11:06Z DEBUG nisDomainObject 2020-06-17T10:11:06Z DEBUG dc: 2020-06-17T10:11:06Z DEBUG lin 2020-06-17T10:11:06Z DEBUG info: 2020-06-17T10:11:06Z DEBUG IPA V2.0 2020-06-17T10:11:06Z DEBUG nisDomain: 2020-06-17T10:11:06Z DEBUG lin.test.lan 2020-06-17T10:11:06Z DEBUG associatedDomain: 2020-06-17T10:11:06Z DEBUG lin.test.lan 2020-06-17T10:11:06Z DEBUG aci: 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:06Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:06Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:11:06Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:06Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG add: '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:06Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG domain 2020-06-17T10:11:06Z DEBUG pilotObject 2020-06-17T10:11:06Z DEBUG domainRelatedObject 2020-06-17T10:11:06Z DEBUG nisDomainObject 2020-06-17T10:11:06Z DEBUG dc: 2020-06-17T10:11:06Z DEBUG lin 2020-06-17T10:11:06Z DEBUG info: 2020-06-17T10:11:06Z DEBUG IPA V2.0 2020-06-17T10:11:06Z DEBUG nisDomain: 2020-06-17T10:11:06Z DEBUG lin.test.lan 2020-06-17T10:11:06Z DEBUG associatedDomain: 2020-06-17T10:11:06Z DEBUG lin.test.lan 2020-06-17T10:11:06Z DEBUG aci: 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:06Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:06Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:11:06Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:06Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG [(0, 'aci', ['(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:11:06Z DEBUG Updated 1 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG New entry: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nestedgroup 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG HBAC Administrator 2020-06-17T10:11:06Z DEBUG description: 2020-06-17T10:11:06Z DEBUG HBAC Administrator 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nestedgroup 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG HBAC Administrator 2020-06-17T10:11:06Z DEBUG description: 2020-06-17T10:11:06Z DEBUG HBAC Administrator 2020-06-17T10:11:06Z DEBUG New entry: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nestedgroup 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Sudo Administrator 2020-06-17T10:11:06Z DEBUG description: 2020-06-17T10:11:06Z DEBUG Sudo Administrator 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nestedgroup 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Sudo Administrator 2020-06-17T10:11:06Z DEBUG description: 2020-06-17T10:11:06Z DEBUG Sudo Administrator 2020-06-17T10:11:06Z DEBUG New entry: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nestedgroup 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Password Policy Administrator 2020-06-17T10:11:06Z DEBUG description: 2020-06-17T10:11:06Z DEBUG Password Policy Administrator 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nestedgroup 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Password Policy Administrator 2020-06-17T10:11:06Z DEBUG description: 2020-06-17T10:11:06Z DEBUG Password Policy Administrator 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=Host Enrollment,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG nestedgroup 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Host Enrollment 2020-06-17T10:11:06Z DEBUG description: 2020-06-17T10:11:06Z DEBUG Host Enrollment 2020-06-17T10:11:06Z DEBUG add: 'cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan' to member, current value [] 2020-06-17T10:11:06Z DEBUG add: updated value ['cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG nestedgroup 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Host Enrollment 2020-06-17T10:11:06Z DEBUG description: 2020-06-17T10:11:06Z DEBUG Host Enrollment 2020-06-17T10:11:06Z DEBUG member: 2020-06-17T10:11:06Z DEBUG cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG [(2, 'member', ['cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:11:06Z DEBUG Updated 1 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG domain 2020-06-17T10:11:06Z DEBUG pilotObject 2020-06-17T10:11:06Z DEBUG domainRelatedObject 2020-06-17T10:11:06Z DEBUG nisDomainObject 2020-06-17T10:11:06Z DEBUG dc: 2020-06-17T10:11:06Z DEBUG lin 2020-06-17T10:11:06Z DEBUG info: 2020-06-17T10:11:06Z DEBUG IPA V2.0 2020-06-17T10:11:06Z DEBUG nisDomain: 2020-06-17T10:11:06Z DEBUG lin.test.lan 2020-06-17T10:11:06Z DEBUG associatedDomain: 2020-06-17T10:11:06Z DEBUG lin.test.lan 2020-06-17T10:11:06Z DEBUG aci: 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:06Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:06Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:11:06Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:06Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "Add DNS entries";allow (add) groupdn = "ldap:///cn=add dns entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:06Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "Add DNS entries";allow (add) groupdn = "ldap:///cn=add dns entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:11:06Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "Remove DNS entries";allow (delete) groupdn = "ldap:///cn=remove dns entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:06Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "Remove DNS entries";allow (delete) groupdn = "ldap:///cn=remove dns entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:11:06Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy")(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "Update DNS entries";allow (write) groupdn = "ldap:///cn=update dns entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:06Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy")(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "Update DNS entries";allow (write) groupdn = "ldap:///cn=update dns entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG domain 2020-06-17T10:11:06Z DEBUG pilotObject 2020-06-17T10:11:06Z DEBUG domainRelatedObject 2020-06-17T10:11:06Z DEBUG nisDomainObject 2020-06-17T10:11:06Z DEBUG dc: 2020-06-17T10:11:06Z DEBUG lin 2020-06-17T10:11:06Z DEBUG info: 2020-06-17T10:11:06Z DEBUG IPA V2.0 2020-06-17T10:11:06Z DEBUG nisDomain: 2020-06-17T10:11:06Z DEBUG lin.test.lan 2020-06-17T10:11:06Z DEBUG associatedDomain: 2020-06-17T10:11:06Z DEBUG lin.test.lan 2020-06-17T10:11:06Z DEBUG aci: 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:11:06Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:06Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:06Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:11:06Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:06Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG [] 2020-06-17T10:11:06Z DEBUG Updated 0 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG New entry: cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG nestedgroup 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG SELinux User Map Administrators 2020-06-17T10:11:06Z DEBUG description: 2020-06-17T10:11:06Z DEBUG SELinux User Map Administrators 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG nestedgroup 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG SELinux User Map Administrators 2020-06-17T10:11:06Z DEBUG description: 2020-06-17T10:11:06Z DEBUG SELinux User Map Administrators 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ipa 2020-06-17T10:11:06Z DEBUG aci: 2020-06-17T10:11:06Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) userdn = "ldap:///fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:06Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) userdn = "ldap:///fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:11:06Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) userdn = "ldap:///fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:06Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) userdn = "ldap:///fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:11:06Z DEBUG add: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:06Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:06Z DEBUG add: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:06Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ipa 2020-06-17T10:11:06Z DEBUG aci: 2020-06-17T10:11:06Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:11:06Z DEBUG Updated 1 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG ipapermission 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Retrieve Certificates from the CA 2020-06-17T10:11:06Z DEBUG member: 2020-06-17T10:11:06Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG add: 'cn=Host Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan' to member, current value ['cn=Certificate Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG add: updated value ['cn=Certificate Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan', 'cn=Host Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG ipapermission 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Retrieve Certificates from the CA 2020-06-17T10:11:06Z DEBUG member: 2020-06-17T10:11:06Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG [(0, 'member', ['cn=Host Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:11:06Z DEBUG Updated 1 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG ipapermission 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Revoke Certificate 2020-06-17T10:11:06Z DEBUG member: 2020-06-17T10:11:06Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG add: 'cn=Host Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan' to member, current value ['cn=Certificate Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG add: updated value ['cn=Certificate Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan', 'cn=Host Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG ipapermission 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Revoke Certificate 2020-06-17T10:11:06Z DEBUG member: 2020-06-17T10:11:06Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG [(0, 'member', ['cn=Host Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:11:06Z DEBUG Updated 1 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ipa 2020-06-17T10:11:06Z DEBUG aci: 2020-06-17T10:11:06Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG remove: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) userdn = "ldap:///fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:06Z DEBUG remove: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) userdn = "ldap:///fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:11:06Z DEBUG add: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:06Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG ipa 2020-06-17T10:11:06Z DEBUG aci: 2020-06-17T10:11:06Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG (target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:11:06Z DEBUG Updated 1 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG Updating existing entry: cn=certificates,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG certificates 2020-06-17T10:11:06Z DEBUG remove: '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) userdn = "ldap:///fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' from aci, current value [] 2020-06-17T10:11:06Z DEBUG remove: '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) userdn = "ldap:///fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:11:06Z DEBUG add: '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value [] 2020-06-17T10:11:06Z DEBUG add: updated value ['(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nsContainer 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG certificates 2020-06-17T10:11:06Z DEBUG aci: 2020-06-17T10:11:06Z DEBUG (targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:06Z DEBUG [(2, 'aci', ['(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:11:06Z DEBUG Updated 1 2020-06-17T10:11:06Z DEBUG Done 2020-06-17T10:11:06Z DEBUG New entry: cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nestedgroup 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Automember Task Administrator 2020-06-17T10:11:06Z DEBUG description: 2020-06-17T10:11:06Z DEBUG Automember Task Administrator 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG nestedgroup 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Automember Task Administrator 2020-06-17T10:11:06Z DEBUG description: 2020-06-17T10:11:06Z DEBUG Automember Task Administrator 2020-06-17T10:11:06Z DEBUG New entry: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Initial value 2020-06-17T10:11:06Z DEBUG dn: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG ipapermission 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Add Automember Rebuild Membership Task 2020-06-17T10:11:06Z DEBUG member: 2020-06-17T10:11:06Z DEBUG cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG ipapermissiontype: 2020-06-17T10:11:06Z DEBUG SYSTEM 2020-06-17T10:11:06Z DEBUG --------------------------------------------- 2020-06-17T10:11:06Z DEBUG Final value after applying updates 2020-06-17T10:11:06Z DEBUG dn: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG objectClass: 2020-06-17T10:11:06Z DEBUG groupofnames 2020-06-17T10:11:06Z DEBUG ipapermission 2020-06-17T10:11:06Z DEBUG top 2020-06-17T10:11:06Z DEBUG cn: 2020-06-17T10:11:06Z DEBUG Add Automember Rebuild Membership Task 2020-06-17T10:11:06Z DEBUG member: 2020-06-17T10:11:06Z DEBUG cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:06Z DEBUG ipapermissiontype: 2020-06-17T10:11:06Z DEBUG SYSTEM 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=config 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=config 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG config 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG nsslapdConfig 2020-06-17T10:11:07Z DEBUG nsslapd-backendconfig: 2020-06-17T10:11:07Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-betype: 2020-06-17T10:11:07Z DEBUG ldbm database 2020-06-17T10:11:07Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:11:07Z DEBUG cn=schema 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG cn=monitor 2020-06-17T10:11:07Z DEBUG cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-plugin: 2020-06-17T10:11:07Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-port 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 10 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:11:07Z DEBUG 16384 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-port: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-workingdir: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-localuser: 2020-06-17T10:11:07Z DEBUG dirsrv 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG passwordInHistory: 2020-06-17T10:11:07Z DEBUG 6 2020-06-17T10:11:07Z DEBUG passwordUnlock: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordGraceLimit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG passwordMustChange: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-sizelimit: 2020-06-17T10:11:07Z DEBUG 2000 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG passwordWarning: 2020-06-17T10:11:07Z DEBUG 86400 2020-06-17T10:11:07Z DEBUG nsslapd-readonly: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-threadnumber: 2020-06-17T10:11:07Z DEBUG 16 2020-06-17T10:11:07Z DEBUG passwordLockout: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-localhost: 2020-06-17T10:11:07Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:11:07Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:11:07Z DEBUG 10000 2020-06-17T10:11:07Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:11:07Z DEBUG 40 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG passwordMinLength: 2020-06-17T10:11:07Z DEBUG 8 2020-06-17T10:11:07Z DEBUG passwordMinDigits: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinAlphas: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinUppers: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinLowers: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinSpecials: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMin8bit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxRepeats: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinCategories: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG passwordMinTokenLength: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG passwordPalindrome: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordDictCheck: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordDictPath: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordUserAttributes: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordBadWords: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordMaxSequence: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxSeqSets: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxClassChars: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-schemacheck: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-schemamod: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-schemareplace: 2020-06-17T10:11:07Z DEBUG replication-only 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 500 2020-06-17T10:11:07Z DEBUG passwordMaxFailure: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:11:07Z DEBUG nsslapd-lastmod: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-security: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordMaxAge: 2020-06-17T10:11:07Z DEBUG 8640000 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG passwordResetFailureCount: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordLegacyPolicy: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-rootpw: 2020-06-17T10:11:07Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:11:07Z DEBUG passwordChange: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:11:07Z DEBUG 256 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG nsslapd-securePort: 2020-06-17T10:11:07Z DEBUG 636 2020-06-17T10:11:07Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-timelimit: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:11:07Z DEBUG 64 2020-06-17T10:11:07Z DEBUG nsslapd-svrtab: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordExp: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordSendExpiringTime: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG day 2020-06-17T10:11:07Z DEBUG passwordLockoutDuration: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-idletimeout: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-nagle: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-csnlogging: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordCheckSyntax: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-listenhost: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-snmp-index: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:11:07Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:11:07Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:11:07Z DEBUG cn=Directory Manager 2020-06-17T10:11:07Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:11:07Z DEBUG uidNumber 2020-06-17T10:11:07Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:11:07Z DEBUG gidNumber 2020-06-17T10:11:07Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:11:07Z DEBUG dc=example,dc=com 2020-06-17T10:11:07Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:11:07Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-counters: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-rootdn: 2020-06-17T10:11:07Z DEBUG cn=Directory Manager 2020-06-17T10:11:07Z DEBUG passwordMinAge: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:11:07Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-result-tweak: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-maxbersize: 2020-06-17T10:11:07Z DEBUG 209715200 2020-06-17T10:11:07Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-versionstring: 2020-06-17T10:11:07Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:11:07Z DEBUG nsslapd-referralmode: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:11:07Z DEBUG 262144 2020-06-17T10:11:07Z DEBUG nsslapd-conntablesize: 2020-06-17T10:11:07Z DEBUG 1024 2020-06-17T10:11:07Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:11:07Z DEBUG allowed 2020-06-17T10:11:07Z DEBUG nsslapd-config: 2020-06-17T10:11:07Z DEBUG cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-instancedir: 2020-06-17T10:11:07Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-schemadir: 2020-06-17T10:11:07Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:11:07Z DEBUG nsslapd-lockdir: 2020-06-17T10:11:07Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-tmpdir: 2020-06-17T10:11:07Z DEBUG /tmp 2020-06-17T10:11:07Z DEBUG nsslapd-certdir: 2020-06-17T10:11:07Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-ldifdir: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:11:07Z DEBUG nsslapd-bakdir: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:11:07Z DEBUG nsslapd-saslpath: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-rundir: 2020-06-17T10:11:07Z DEBUG /var/run/dirsrv 2020-06-17T10:11:07Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:11:07Z DEBUG 300000 2020-06-17T10:11:07Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-localssf: 2020-06-17T10:11:07Z DEBUG 71 2020-06-17T10:11:07Z DEBUG nsslapd-minssf: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:11:07Z DEBUG next 2020-06-17T10:11:07Z DEBUG nsslapd-validate-cert: 2020-06-17T10:11:07Z DEBUG warn 2020-06-17T10:11:07Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:11:07Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:11:07Z DEBUG 60 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:11:07Z DEBUG 20971520 2020-06-17T10:11:07Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:11:07Z DEBUG nolog 2020-06-17T10:11:07Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:11:07Z DEBUG 128 2020-06-17T10:11:07Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:11:07Z DEBUG -1 2020-06-17T10:11:07Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:11:07Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-logging-backend: 2020-06-17T10:11:07Z DEBUG dirsrv-log 2020-06-17T10:11:07Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:11:07Z DEBUG none 2020-06-17T10:11:07Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:11:07Z DEBUG warn-invalid 2020-06-17T10:11:07Z DEBUG passwordStorageScheme: 2020-06-17T10:11:07Z DEBUG PBKDF2_SHA256 2020-06-17T10:11:07Z DEBUG passwordAdminDN: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:11:07Z DEBUG PBKDF2_SHA256 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-hash-filters: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:11:07Z DEBUG add: '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2020-06-17T10:11:07Z DEBUG add: updated value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=config 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG config 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG nsslapdConfig 2020-06-17T10:11:07Z DEBUG nsslapd-backendconfig: 2020-06-17T10:11:07Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-betype: 2020-06-17T10:11:07Z DEBUG ldbm database 2020-06-17T10:11:07Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:11:07Z DEBUG cn=schema 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG cn=monitor 2020-06-17T10:11:07Z DEBUG cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-plugin: 2020-06-17T10:11:07Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-port 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 10 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:11:07Z DEBUG 16384 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-port: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-workingdir: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-localuser: 2020-06-17T10:11:07Z DEBUG dirsrv 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG passwordInHistory: 2020-06-17T10:11:07Z DEBUG 6 2020-06-17T10:11:07Z DEBUG passwordUnlock: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordGraceLimit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG passwordMustChange: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-sizelimit: 2020-06-17T10:11:07Z DEBUG 2000 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG passwordWarning: 2020-06-17T10:11:07Z DEBUG 86400 2020-06-17T10:11:07Z DEBUG nsslapd-readonly: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-threadnumber: 2020-06-17T10:11:07Z DEBUG 16 2020-06-17T10:11:07Z DEBUG passwordLockout: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-localhost: 2020-06-17T10:11:07Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:11:07Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:11:07Z DEBUG 10000 2020-06-17T10:11:07Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:11:07Z DEBUG 40 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG passwordMinLength: 2020-06-17T10:11:07Z DEBUG 8 2020-06-17T10:11:07Z DEBUG passwordMinDigits: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinAlphas: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinUppers: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinLowers: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinSpecials: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMin8bit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxRepeats: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinCategories: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG passwordMinTokenLength: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG passwordPalindrome: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordDictCheck: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordDictPath: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordUserAttributes: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordBadWords: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordMaxSequence: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxSeqSets: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxClassChars: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-schemacheck: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-schemamod: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-schemareplace: 2020-06-17T10:11:07Z DEBUG replication-only 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 500 2020-06-17T10:11:07Z DEBUG passwordMaxFailure: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:11:07Z DEBUG nsslapd-lastmod: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-security: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordMaxAge: 2020-06-17T10:11:07Z DEBUG 8640000 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG passwordResetFailureCount: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordLegacyPolicy: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-rootpw: 2020-06-17T10:11:07Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:11:07Z DEBUG passwordChange: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:11:07Z DEBUG 256 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG nsslapd-securePort: 2020-06-17T10:11:07Z DEBUG 636 2020-06-17T10:11:07Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-timelimit: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:11:07Z DEBUG 64 2020-06-17T10:11:07Z DEBUG nsslapd-svrtab: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordExp: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordSendExpiringTime: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG day 2020-06-17T10:11:07Z DEBUG passwordLockoutDuration: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-idletimeout: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-nagle: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-csnlogging: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordCheckSyntax: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-listenhost: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-snmp-index: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:11:07Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:11:07Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:11:07Z DEBUG cn=Directory Manager 2020-06-17T10:11:07Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:11:07Z DEBUG uidNumber 2020-06-17T10:11:07Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:11:07Z DEBUG gidNumber 2020-06-17T10:11:07Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:11:07Z DEBUG dc=example,dc=com 2020-06-17T10:11:07Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:11:07Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-counters: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-rootdn: 2020-06-17T10:11:07Z DEBUG cn=Directory Manager 2020-06-17T10:11:07Z DEBUG passwordMinAge: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:11:07Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-result-tweak: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-maxbersize: 2020-06-17T10:11:07Z DEBUG 209715200 2020-06-17T10:11:07Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-versionstring: 2020-06-17T10:11:07Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:11:07Z DEBUG nsslapd-referralmode: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:11:07Z DEBUG 262144 2020-06-17T10:11:07Z DEBUG nsslapd-conntablesize: 2020-06-17T10:11:07Z DEBUG 1024 2020-06-17T10:11:07Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:11:07Z DEBUG allowed 2020-06-17T10:11:07Z DEBUG nsslapd-config: 2020-06-17T10:11:07Z DEBUG cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-instancedir: 2020-06-17T10:11:07Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-schemadir: 2020-06-17T10:11:07Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:11:07Z DEBUG nsslapd-lockdir: 2020-06-17T10:11:07Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-tmpdir: 2020-06-17T10:11:07Z DEBUG /tmp 2020-06-17T10:11:07Z DEBUG nsslapd-certdir: 2020-06-17T10:11:07Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-ldifdir: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:11:07Z DEBUG nsslapd-bakdir: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:11:07Z DEBUG nsslapd-saslpath: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-rundir: 2020-06-17T10:11:07Z DEBUG /var/run/dirsrv 2020-06-17T10:11:07Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:11:07Z DEBUG 300000 2020-06-17T10:11:07Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-localssf: 2020-06-17T10:11:07Z DEBUG 71 2020-06-17T10:11:07Z DEBUG nsslapd-minssf: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:11:07Z DEBUG next 2020-06-17T10:11:07Z DEBUG nsslapd-validate-cert: 2020-06-17T10:11:07Z DEBUG warn 2020-06-17T10:11:07Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:11:07Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:11:07Z DEBUG 60 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:11:07Z DEBUG 20971520 2020-06-17T10:11:07Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:11:07Z DEBUG nolog 2020-06-17T10:11:07Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:11:07Z DEBUG 128 2020-06-17T10:11:07Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:11:07Z DEBUG -1 2020-06-17T10:11:07Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:11:07Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-logging-backend: 2020-06-17T10:11:07Z DEBUG dirsrv-log 2020-06-17T10:11:07Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:11:07Z DEBUG none 2020-06-17T10:11:07Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:11:07Z DEBUG warn-invalid 2020-06-17T10:11:07Z DEBUG passwordStorageScheme: 2020-06-17T10:11:07Z DEBUG PBKDF2_SHA256 2020-06-17T10:11:07Z DEBUG passwordAdminDN: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:11:07Z DEBUG PBKDF2_SHA256 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-hash-filters: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:11:07Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:11:07Z DEBUG Updated 1 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG New entry: cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG retrieve certificate 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG retrieve certificate 2020-06-17T10:11:07Z DEBUG New entry: cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG request certificate 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG request certificate 2020-06-17T10:11:07Z DEBUG New entry: cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG request certificate different host 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG request certificate different host 2020-06-17T10:11:07Z DEBUG New entry: cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG certificate status 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG certificate status 2020-06-17T10:11:07Z DEBUG New entry: cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG revoke certificate 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG revoke certificate 2020-06-17T10:11:07Z DEBUG New entry: cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG certificate remove hold 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG certificate remove hold 2020-06-17T10:11:07Z DEBUG New entry: cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG request certificate ignore caacl 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG request certificate ignore caacl 2020-06-17T10:11:07Z DEBUG New entry: cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG ipapermission 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Request Certificate ignoring CA ACLs 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG ipapermission 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Request Certificate ignoring CA ACLs 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG Updating existing entry: dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG domain 2020-06-17T10:11:07Z DEBUG pilotObject 2020-06-17T10:11:07Z DEBUG domainRelatedObject 2020-06-17T10:11:07Z DEBUG nisDomainObject 2020-06-17T10:11:07Z DEBUG dc: 2020-06-17T10:11:07Z DEBUG lin 2020-06-17T10:11:07Z DEBUG info: 2020-06-17T10:11:07Z DEBUG IPA V2.0 2020-06-17T10:11:07Z DEBUG nisDomain: 2020-06-17T10:11:07Z DEBUG lin.test.lan 2020-06-17T10:11:07Z DEBUG associatedDomain: 2020-06-17T10:11:07Z DEBUG lin.test.lan 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:11:07Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:07Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:07Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:11:07Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:11:07Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:07Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:07Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:11:07Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:07Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG add: '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG domain 2020-06-17T10:11:07Z DEBUG pilotObject 2020-06-17T10:11:07Z DEBUG domainRelatedObject 2020-06-17T10:11:07Z DEBUG nisDomainObject 2020-06-17T10:11:07Z DEBUG dc: 2020-06-17T10:11:07Z DEBUG lin 2020-06-17T10:11:07Z DEBUG info: 2020-06-17T10:11:07Z DEBUG IPA V2.0 2020-06-17T10:11:07Z DEBUG nisDomain: 2020-06-17T10:11:07Z DEBUG lin.test.lan 2020-06-17T10:11:07Z DEBUG associatedDomain: 2020-06-17T10:11:07Z DEBUG lin.test.lan 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:11:07Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:07Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:07Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:11:07Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:11:07Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:07Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:07Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:11:07Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:07Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG [(0, 'aci', ['(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:11:07Z DEBUG Updated 1 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG New entry: cn=RBAC Readers,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=RBAC Readers,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG RBAC Readers 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Read roles, privileges, permissions and ACIs 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=RBAC Readers,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG RBAC Readers 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Read roles, privileges, permissions and ACIs 2020-06-17T10:11:07Z DEBUG New entry: cn=Password Policy Readers,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Password Policy Readers,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Password Policy Readers 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Read password policies 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Password Policy Readers,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Password Policy Readers 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Read password policies 2020-06-17T10:11:07Z DEBUG New entry: cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Kerberos Ticket Policy Readers 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Read global and per-user Kerberos ticket policy 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Kerberos Ticket Policy Readers 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Read global and per-user Kerberos ticket policy 2020-06-17T10:11:07Z DEBUG New entry: cn=Automember Readers,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Automember Readers,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Automember Readers 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Read Automember definitions 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Automember Readers,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Automember Readers 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Read Automember definitions 2020-06-17T10:11:07Z DEBUG New entry: cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG IPA Masters Readers 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Read list of IPA masters 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG IPA Masters Readers 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Read list of IPA masters 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG masters 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) userdn = "ldap:///fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) userdn = "ldap:///fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) userdn = "ldap:///fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) userdn = "ldap:///fqdn=freeipaserver.lin.test.lan,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:11:07Z DEBUG add: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG add: updated value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG add: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG add: updated value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG masters 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG [(0, 'aci', ['(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:11:07Z DEBUG Updated 1 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG New entry: cn=PassSync Service,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=PassSync Service,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG PassSync Service 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG PassSync Service 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=PassSync Service,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG PassSync Service 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG PassSync Service 2020-06-17T10:11:07Z DEBUG New entry: cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG ipapermission 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Read PassSync Managers Configuration 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG ipapermissiontype: 2020-06-17T10:11:07Z DEBUG SYSTEM 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG ipapermission 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Read PassSync Managers Configuration 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG ipapermissiontype: 2020-06-17T10:11:07Z DEBUG SYSTEM 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=config 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=config 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG config 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG nsslapdConfig 2020-06-17T10:11:07Z DEBUG nsslapd-backendconfig: 2020-06-17T10:11:07Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-betype: 2020-06-17T10:11:07Z DEBUG ldbm database 2020-06-17T10:11:07Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:11:07Z DEBUG cn=schema 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG cn=monitor 2020-06-17T10:11:07Z DEBUG cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-plugin: 2020-06-17T10:11:07Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-port 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 10 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:11:07Z DEBUG 16384 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-port: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-workingdir: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-localuser: 2020-06-17T10:11:07Z DEBUG dirsrv 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG passwordInHistory: 2020-06-17T10:11:07Z DEBUG 6 2020-06-17T10:11:07Z DEBUG passwordUnlock: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordGraceLimit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG passwordMustChange: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-sizelimit: 2020-06-17T10:11:07Z DEBUG 2000 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG passwordWarning: 2020-06-17T10:11:07Z DEBUG 86400 2020-06-17T10:11:07Z DEBUG nsslapd-readonly: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-threadnumber: 2020-06-17T10:11:07Z DEBUG 16 2020-06-17T10:11:07Z DEBUG passwordLockout: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-localhost: 2020-06-17T10:11:07Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:11:07Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:11:07Z DEBUG 10000 2020-06-17T10:11:07Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:11:07Z DEBUG 40 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG passwordMinLength: 2020-06-17T10:11:07Z DEBUG 8 2020-06-17T10:11:07Z DEBUG passwordMinDigits: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinAlphas: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinUppers: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinLowers: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinSpecials: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMin8bit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxRepeats: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinCategories: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG passwordMinTokenLength: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG passwordPalindrome: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordDictCheck: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordDictPath: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordUserAttributes: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordBadWords: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordMaxSequence: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxSeqSets: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxClassChars: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-schemacheck: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-schemamod: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-schemareplace: 2020-06-17T10:11:07Z DEBUG replication-only 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 500 2020-06-17T10:11:07Z DEBUG passwordMaxFailure: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:11:07Z DEBUG nsslapd-lastmod: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-security: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordMaxAge: 2020-06-17T10:11:07Z DEBUG 8640000 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG passwordResetFailureCount: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordLegacyPolicy: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-rootpw: 2020-06-17T10:11:07Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:11:07Z DEBUG passwordChange: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:11:07Z DEBUG 256 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG nsslapd-securePort: 2020-06-17T10:11:07Z DEBUG 636 2020-06-17T10:11:07Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-timelimit: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:11:07Z DEBUG 64 2020-06-17T10:11:07Z DEBUG nsslapd-svrtab: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordExp: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordSendExpiringTime: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG day 2020-06-17T10:11:07Z DEBUG passwordLockoutDuration: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-idletimeout: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-nagle: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-csnlogging: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordCheckSyntax: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-listenhost: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-snmp-index: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:11:07Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:11:07Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:11:07Z DEBUG cn=Directory Manager 2020-06-17T10:11:07Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:11:07Z DEBUG uidNumber 2020-06-17T10:11:07Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:11:07Z DEBUG gidNumber 2020-06-17T10:11:07Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:11:07Z DEBUG dc=example,dc=com 2020-06-17T10:11:07Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:11:07Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-counters: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-rootdn: 2020-06-17T10:11:07Z DEBUG cn=Directory Manager 2020-06-17T10:11:07Z DEBUG passwordMinAge: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:11:07Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-result-tweak: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-maxbersize: 2020-06-17T10:11:07Z DEBUG 209715200 2020-06-17T10:11:07Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-versionstring: 2020-06-17T10:11:07Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:11:07Z DEBUG nsslapd-referralmode: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:11:07Z DEBUG 262144 2020-06-17T10:11:07Z DEBUG nsslapd-conntablesize: 2020-06-17T10:11:07Z DEBUG 1024 2020-06-17T10:11:07Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:11:07Z DEBUG allowed 2020-06-17T10:11:07Z DEBUG nsslapd-config: 2020-06-17T10:11:07Z DEBUG cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-instancedir: 2020-06-17T10:11:07Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-schemadir: 2020-06-17T10:11:07Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:11:07Z DEBUG nsslapd-lockdir: 2020-06-17T10:11:07Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-tmpdir: 2020-06-17T10:11:07Z DEBUG /tmp 2020-06-17T10:11:07Z DEBUG nsslapd-certdir: 2020-06-17T10:11:07Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-ldifdir: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:11:07Z DEBUG nsslapd-bakdir: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:11:07Z DEBUG nsslapd-saslpath: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-rundir: 2020-06-17T10:11:07Z DEBUG /var/run/dirsrv 2020-06-17T10:11:07Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:11:07Z DEBUG 300000 2020-06-17T10:11:07Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-localssf: 2020-06-17T10:11:07Z DEBUG 71 2020-06-17T10:11:07Z DEBUG nsslapd-minssf: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:11:07Z DEBUG next 2020-06-17T10:11:07Z DEBUG nsslapd-validate-cert: 2020-06-17T10:11:07Z DEBUG warn 2020-06-17T10:11:07Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:11:07Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:11:07Z DEBUG 60 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:11:07Z DEBUG 20971520 2020-06-17T10:11:07Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:11:07Z DEBUG nolog 2020-06-17T10:11:07Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:11:07Z DEBUG 128 2020-06-17T10:11:07Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:11:07Z DEBUG -1 2020-06-17T10:11:07Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:11:07Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-logging-backend: 2020-06-17T10:11:07Z DEBUG dirsrv-log 2020-06-17T10:11:07Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:11:07Z DEBUG none 2020-06-17T10:11:07Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:11:07Z DEBUG warn-invalid 2020-06-17T10:11:07Z DEBUG passwordStorageScheme: 2020-06-17T10:11:07Z DEBUG PBKDF2_SHA256 2020-06-17T10:11:07Z DEBUG passwordAdminDN: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:11:07Z DEBUG PBKDF2_SHA256 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-hash-filters: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:11:07Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG add: '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG add: updated value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=config 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG config 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG nsslapdConfig 2020-06-17T10:11:07Z DEBUG nsslapd-backendconfig: 2020-06-17T10:11:07Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-betype: 2020-06-17T10:11:07Z DEBUG ldbm database 2020-06-17T10:11:07Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:11:07Z DEBUG cn=schema 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG cn=monitor 2020-06-17T10:11:07Z DEBUG cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-plugin: 2020-06-17T10:11:07Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-port 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 10 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:11:07Z DEBUG 16384 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-port: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-workingdir: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-localuser: 2020-06-17T10:11:07Z DEBUG dirsrv 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG passwordInHistory: 2020-06-17T10:11:07Z DEBUG 6 2020-06-17T10:11:07Z DEBUG passwordUnlock: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordGraceLimit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG passwordMustChange: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-sizelimit: 2020-06-17T10:11:07Z DEBUG 2000 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG passwordWarning: 2020-06-17T10:11:07Z DEBUG 86400 2020-06-17T10:11:07Z DEBUG nsslapd-readonly: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-threadnumber: 2020-06-17T10:11:07Z DEBUG 16 2020-06-17T10:11:07Z DEBUG passwordLockout: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-localhost: 2020-06-17T10:11:07Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:11:07Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:11:07Z DEBUG 10000 2020-06-17T10:11:07Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:11:07Z DEBUG 40 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG passwordMinLength: 2020-06-17T10:11:07Z DEBUG 8 2020-06-17T10:11:07Z DEBUG passwordMinDigits: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinAlphas: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinUppers: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinLowers: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinSpecials: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMin8bit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxRepeats: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinCategories: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG passwordMinTokenLength: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG passwordPalindrome: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordDictCheck: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordDictPath: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordUserAttributes: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordBadWords: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordMaxSequence: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxSeqSets: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxClassChars: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-schemacheck: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-schemamod: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-schemareplace: 2020-06-17T10:11:07Z DEBUG replication-only 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 500 2020-06-17T10:11:07Z DEBUG passwordMaxFailure: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:11:07Z DEBUG nsslapd-lastmod: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-security: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordMaxAge: 2020-06-17T10:11:07Z DEBUG 8640000 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG passwordResetFailureCount: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordLegacyPolicy: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-rootpw: 2020-06-17T10:11:07Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:11:07Z DEBUG passwordChange: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:11:07Z DEBUG 256 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG nsslapd-securePort: 2020-06-17T10:11:07Z DEBUG 636 2020-06-17T10:11:07Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-timelimit: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:11:07Z DEBUG 64 2020-06-17T10:11:07Z DEBUG nsslapd-svrtab: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordExp: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordSendExpiringTime: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG day 2020-06-17T10:11:07Z DEBUG passwordLockoutDuration: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-idletimeout: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-nagle: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-csnlogging: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordCheckSyntax: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-listenhost: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-snmp-index: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:11:07Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:11:07Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:11:07Z DEBUG cn=Directory Manager 2020-06-17T10:11:07Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:11:07Z DEBUG uidNumber 2020-06-17T10:11:07Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:11:07Z DEBUG gidNumber 2020-06-17T10:11:07Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:11:07Z DEBUG dc=example,dc=com 2020-06-17T10:11:07Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:11:07Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-counters: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-rootdn: 2020-06-17T10:11:07Z DEBUG cn=Directory Manager 2020-06-17T10:11:07Z DEBUG passwordMinAge: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:11:07Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-result-tweak: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-maxbersize: 2020-06-17T10:11:07Z DEBUG 209715200 2020-06-17T10:11:07Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-versionstring: 2020-06-17T10:11:07Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:11:07Z DEBUG nsslapd-referralmode: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:11:07Z DEBUG 262144 2020-06-17T10:11:07Z DEBUG nsslapd-conntablesize: 2020-06-17T10:11:07Z DEBUG 1024 2020-06-17T10:11:07Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:11:07Z DEBUG allowed 2020-06-17T10:11:07Z DEBUG nsslapd-config: 2020-06-17T10:11:07Z DEBUG cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-instancedir: 2020-06-17T10:11:07Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-schemadir: 2020-06-17T10:11:07Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:11:07Z DEBUG nsslapd-lockdir: 2020-06-17T10:11:07Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-tmpdir: 2020-06-17T10:11:07Z DEBUG /tmp 2020-06-17T10:11:07Z DEBUG nsslapd-certdir: 2020-06-17T10:11:07Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-ldifdir: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:11:07Z DEBUG nsslapd-bakdir: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:11:07Z DEBUG nsslapd-saslpath: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-rundir: 2020-06-17T10:11:07Z DEBUG /var/run/dirsrv 2020-06-17T10:11:07Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:11:07Z DEBUG 300000 2020-06-17T10:11:07Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-localssf: 2020-06-17T10:11:07Z DEBUG 71 2020-06-17T10:11:07Z DEBUG nsslapd-minssf: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:11:07Z DEBUG next 2020-06-17T10:11:07Z DEBUG nsslapd-validate-cert: 2020-06-17T10:11:07Z DEBUG warn 2020-06-17T10:11:07Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:11:07Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:11:07Z DEBUG 60 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:11:07Z DEBUG 20971520 2020-06-17T10:11:07Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:11:07Z DEBUG nolog 2020-06-17T10:11:07Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:11:07Z DEBUG 128 2020-06-17T10:11:07Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:11:07Z DEBUG -1 2020-06-17T10:11:07Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:11:07Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-logging-backend: 2020-06-17T10:11:07Z DEBUG dirsrv-log 2020-06-17T10:11:07Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:11:07Z DEBUG none 2020-06-17T10:11:07Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:11:07Z DEBUG warn-invalid 2020-06-17T10:11:07Z DEBUG passwordStorageScheme: 2020-06-17T10:11:07Z DEBUG PBKDF2_SHA256 2020-06-17T10:11:07Z DEBUG passwordAdminDN: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:11:07Z DEBUG PBKDF2_SHA256 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-hash-filters: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:11:07Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG [(0, 'aci', ['(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:11:07Z DEBUG Updated 1 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG New entry: cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG ipapermission 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Modify PassSync Managers Configuration 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG ipapermissiontype: 2020-06-17T10:11:07Z DEBUG SYSTEM 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG ipapermission 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Modify PassSync Managers Configuration 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG ipapermissiontype: 2020-06-17T10:11:07Z DEBUG SYSTEM 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=config 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=config 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG config 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG nsslapdConfig 2020-06-17T10:11:07Z DEBUG nsslapd-backendconfig: 2020-06-17T10:11:07Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-betype: 2020-06-17T10:11:07Z DEBUG ldbm database 2020-06-17T10:11:07Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:11:07Z DEBUG cn=schema 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG cn=monitor 2020-06-17T10:11:07Z DEBUG cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-plugin: 2020-06-17T10:11:07Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-port 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 10 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:11:07Z DEBUG 16384 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-port: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-workingdir: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-localuser: 2020-06-17T10:11:07Z DEBUG dirsrv 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG passwordInHistory: 2020-06-17T10:11:07Z DEBUG 6 2020-06-17T10:11:07Z DEBUG passwordUnlock: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordGraceLimit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG passwordMustChange: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-sizelimit: 2020-06-17T10:11:07Z DEBUG 2000 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG passwordWarning: 2020-06-17T10:11:07Z DEBUG 86400 2020-06-17T10:11:07Z DEBUG nsslapd-readonly: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-threadnumber: 2020-06-17T10:11:07Z DEBUG 16 2020-06-17T10:11:07Z DEBUG passwordLockout: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-localhost: 2020-06-17T10:11:07Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:11:07Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:11:07Z DEBUG 10000 2020-06-17T10:11:07Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:11:07Z DEBUG 40 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG passwordMinLength: 2020-06-17T10:11:07Z DEBUG 8 2020-06-17T10:11:07Z DEBUG passwordMinDigits: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinAlphas: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinUppers: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinLowers: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinSpecials: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMin8bit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxRepeats: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinCategories: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG passwordMinTokenLength: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG passwordPalindrome: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordDictCheck: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordDictPath: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordUserAttributes: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordBadWords: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordMaxSequence: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxSeqSets: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxClassChars: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-schemacheck: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-schemamod: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-schemareplace: 2020-06-17T10:11:07Z DEBUG replication-only 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 500 2020-06-17T10:11:07Z DEBUG passwordMaxFailure: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:11:07Z DEBUG nsslapd-lastmod: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-security: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordMaxAge: 2020-06-17T10:11:07Z DEBUG 8640000 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG passwordResetFailureCount: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordLegacyPolicy: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-rootpw: 2020-06-17T10:11:07Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:11:07Z DEBUG passwordChange: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:11:07Z DEBUG 256 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG nsslapd-securePort: 2020-06-17T10:11:07Z DEBUG 636 2020-06-17T10:11:07Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-timelimit: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:11:07Z DEBUG 64 2020-06-17T10:11:07Z DEBUG nsslapd-svrtab: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordExp: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordSendExpiringTime: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG day 2020-06-17T10:11:07Z DEBUG passwordLockoutDuration: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-idletimeout: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-nagle: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-csnlogging: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordCheckSyntax: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-listenhost: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-snmp-index: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:11:07Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:11:07Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:11:07Z DEBUG cn=Directory Manager 2020-06-17T10:11:07Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:11:07Z DEBUG uidNumber 2020-06-17T10:11:07Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:11:07Z DEBUG gidNumber 2020-06-17T10:11:07Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:11:07Z DEBUG dc=example,dc=com 2020-06-17T10:11:07Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:11:07Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-counters: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-rootdn: 2020-06-17T10:11:07Z DEBUG cn=Directory Manager 2020-06-17T10:11:07Z DEBUG passwordMinAge: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:11:07Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-result-tweak: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-maxbersize: 2020-06-17T10:11:07Z DEBUG 209715200 2020-06-17T10:11:07Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-versionstring: 2020-06-17T10:11:07Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:11:07Z DEBUG nsslapd-referralmode: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:11:07Z DEBUG 262144 2020-06-17T10:11:07Z DEBUG nsslapd-conntablesize: 2020-06-17T10:11:07Z DEBUG 1024 2020-06-17T10:11:07Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:11:07Z DEBUG allowed 2020-06-17T10:11:07Z DEBUG nsslapd-config: 2020-06-17T10:11:07Z DEBUG cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-instancedir: 2020-06-17T10:11:07Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-schemadir: 2020-06-17T10:11:07Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:11:07Z DEBUG nsslapd-lockdir: 2020-06-17T10:11:07Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-tmpdir: 2020-06-17T10:11:07Z DEBUG /tmp 2020-06-17T10:11:07Z DEBUG nsslapd-certdir: 2020-06-17T10:11:07Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-ldifdir: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:11:07Z DEBUG nsslapd-bakdir: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:11:07Z DEBUG nsslapd-saslpath: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-rundir: 2020-06-17T10:11:07Z DEBUG /var/run/dirsrv 2020-06-17T10:11:07Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:11:07Z DEBUG 300000 2020-06-17T10:11:07Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-localssf: 2020-06-17T10:11:07Z DEBUG 71 2020-06-17T10:11:07Z DEBUG nsslapd-minssf: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:11:07Z DEBUG next 2020-06-17T10:11:07Z DEBUG nsslapd-validate-cert: 2020-06-17T10:11:07Z DEBUG warn 2020-06-17T10:11:07Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:11:07Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:11:07Z DEBUG 60 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:11:07Z DEBUG 20971520 2020-06-17T10:11:07Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:11:07Z DEBUG nolog 2020-06-17T10:11:07Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:11:07Z DEBUG 128 2020-06-17T10:11:07Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:11:07Z DEBUG -1 2020-06-17T10:11:07Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:11:07Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-logging-backend: 2020-06-17T10:11:07Z DEBUG dirsrv-log 2020-06-17T10:11:07Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:11:07Z DEBUG none 2020-06-17T10:11:07Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:11:07Z DEBUG warn-invalid 2020-06-17T10:11:07Z DEBUG passwordStorageScheme: 2020-06-17T10:11:07Z DEBUG PBKDF2_SHA256 2020-06-17T10:11:07Z DEBUG passwordAdminDN: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:11:07Z DEBUG PBKDF2_SHA256 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-hash-filters: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:11:07Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG add: '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG add: updated value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=config 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG config 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG nsslapdConfig 2020-06-17T10:11:07Z DEBUG nsslapd-backendconfig: 2020-06-17T10:11:07Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-betype: 2020-06-17T10:11:07Z DEBUG ldbm database 2020-06-17T10:11:07Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:11:07Z DEBUG cn=schema 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG cn=monitor 2020-06-17T10:11:07Z DEBUG cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-plugin: 2020-06-17T10:11:07Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-port 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 10 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:11:07Z DEBUG 16384 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-port: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-workingdir: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-localuser: 2020-06-17T10:11:07Z DEBUG dirsrv 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG passwordInHistory: 2020-06-17T10:11:07Z DEBUG 6 2020-06-17T10:11:07Z DEBUG passwordUnlock: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordGraceLimit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG passwordMustChange: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-sizelimit: 2020-06-17T10:11:07Z DEBUG 2000 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG passwordWarning: 2020-06-17T10:11:07Z DEBUG 86400 2020-06-17T10:11:07Z DEBUG nsslapd-readonly: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-threadnumber: 2020-06-17T10:11:07Z DEBUG 16 2020-06-17T10:11:07Z DEBUG passwordLockout: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-localhost: 2020-06-17T10:11:07Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:11:07Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:11:07Z DEBUG 10000 2020-06-17T10:11:07Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:11:07Z DEBUG 40 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG passwordMinLength: 2020-06-17T10:11:07Z DEBUG 8 2020-06-17T10:11:07Z DEBUG passwordMinDigits: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinAlphas: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinUppers: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinLowers: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinSpecials: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMin8bit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxRepeats: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinCategories: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG passwordMinTokenLength: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG passwordPalindrome: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordDictCheck: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordDictPath: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordUserAttributes: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordBadWords: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordMaxSequence: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxSeqSets: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxClassChars: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-schemacheck: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-schemamod: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-schemareplace: 2020-06-17T10:11:07Z DEBUG replication-only 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 500 2020-06-17T10:11:07Z DEBUG passwordMaxFailure: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:11:07Z DEBUG nsslapd-lastmod: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-security: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordMaxAge: 2020-06-17T10:11:07Z DEBUG 8640000 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG passwordResetFailureCount: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordLegacyPolicy: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-rootpw: 2020-06-17T10:11:07Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:11:07Z DEBUG passwordChange: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:11:07Z DEBUG 256 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG nsslapd-securePort: 2020-06-17T10:11:07Z DEBUG 636 2020-06-17T10:11:07Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-timelimit: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:11:07Z DEBUG 64 2020-06-17T10:11:07Z DEBUG nsslapd-svrtab: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordExp: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordSendExpiringTime: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG day 2020-06-17T10:11:07Z DEBUG passwordLockoutDuration: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-idletimeout: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-nagle: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-csnlogging: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordCheckSyntax: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-listenhost: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-snmp-index: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:11:07Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:11:07Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:11:07Z DEBUG cn=Directory Manager 2020-06-17T10:11:07Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:11:07Z DEBUG uidNumber 2020-06-17T10:11:07Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:11:07Z DEBUG gidNumber 2020-06-17T10:11:07Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:11:07Z DEBUG dc=example,dc=com 2020-06-17T10:11:07Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:11:07Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-counters: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-rootdn: 2020-06-17T10:11:07Z DEBUG cn=Directory Manager 2020-06-17T10:11:07Z DEBUG passwordMinAge: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:11:07Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-result-tweak: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-maxbersize: 2020-06-17T10:11:07Z DEBUG 209715200 2020-06-17T10:11:07Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-versionstring: 2020-06-17T10:11:07Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:11:07Z DEBUG nsslapd-referralmode: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:11:07Z DEBUG 262144 2020-06-17T10:11:07Z DEBUG nsslapd-conntablesize: 2020-06-17T10:11:07Z DEBUG 1024 2020-06-17T10:11:07Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:11:07Z DEBUG allowed 2020-06-17T10:11:07Z DEBUG nsslapd-config: 2020-06-17T10:11:07Z DEBUG cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-instancedir: 2020-06-17T10:11:07Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-schemadir: 2020-06-17T10:11:07Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:11:07Z DEBUG nsslapd-lockdir: 2020-06-17T10:11:07Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-tmpdir: 2020-06-17T10:11:07Z DEBUG /tmp 2020-06-17T10:11:07Z DEBUG nsslapd-certdir: 2020-06-17T10:11:07Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-ldifdir: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:11:07Z DEBUG nsslapd-bakdir: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:11:07Z DEBUG nsslapd-saslpath: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-rundir: 2020-06-17T10:11:07Z DEBUG /var/run/dirsrv 2020-06-17T10:11:07Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:11:07Z DEBUG 300000 2020-06-17T10:11:07Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-localssf: 2020-06-17T10:11:07Z DEBUG 71 2020-06-17T10:11:07Z DEBUG nsslapd-minssf: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:11:07Z DEBUG next 2020-06-17T10:11:07Z DEBUG nsslapd-validate-cert: 2020-06-17T10:11:07Z DEBUG warn 2020-06-17T10:11:07Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:11:07Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:11:07Z DEBUG 60 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:11:07Z DEBUG 20971520 2020-06-17T10:11:07Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:11:07Z DEBUG nolog 2020-06-17T10:11:07Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:11:07Z DEBUG 128 2020-06-17T10:11:07Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:11:07Z DEBUG -1 2020-06-17T10:11:07Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:11:07Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-logging-backend: 2020-06-17T10:11:07Z DEBUG dirsrv-log 2020-06-17T10:11:07Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:11:07Z DEBUG none 2020-06-17T10:11:07Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:11:07Z DEBUG warn-invalid 2020-06-17T10:11:07Z DEBUG passwordStorageScheme: 2020-06-17T10:11:07Z DEBUG PBKDF2_SHA256 2020-06-17T10:11:07Z DEBUG passwordAdminDN: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:11:07Z DEBUG PBKDF2_SHA256 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-hash-filters: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:11:07Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG [(0, 'aci', ['(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:11:07Z DEBUG Updated 1 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG New entry: cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG ipapermission 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Read LDBM Database Configuration 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG ipapermissiontype: 2020-06-17T10:11:07Z DEBUG SYSTEM 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG ipapermission 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Read LDBM Database Configuration 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG ipapermissiontype: 2020-06-17T10:11:07Z DEBUG SYSTEM 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=config 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=config 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG config 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG nsslapdConfig 2020-06-17T10:11:07Z DEBUG nsslapd-backendconfig: 2020-06-17T10:11:07Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-betype: 2020-06-17T10:11:07Z DEBUG ldbm database 2020-06-17T10:11:07Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:11:07Z DEBUG cn=schema 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG cn=monitor 2020-06-17T10:11:07Z DEBUG cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-plugin: 2020-06-17T10:11:07Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-port 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 10 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:11:07Z DEBUG 16384 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-port: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-workingdir: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-localuser: 2020-06-17T10:11:07Z DEBUG dirsrv 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG passwordInHistory: 2020-06-17T10:11:07Z DEBUG 6 2020-06-17T10:11:07Z DEBUG passwordUnlock: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordGraceLimit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG passwordMustChange: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-sizelimit: 2020-06-17T10:11:07Z DEBUG 2000 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG passwordWarning: 2020-06-17T10:11:07Z DEBUG 86400 2020-06-17T10:11:07Z DEBUG nsslapd-readonly: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-threadnumber: 2020-06-17T10:11:07Z DEBUG 16 2020-06-17T10:11:07Z DEBUG passwordLockout: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-localhost: 2020-06-17T10:11:07Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:11:07Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:11:07Z DEBUG 10000 2020-06-17T10:11:07Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:11:07Z DEBUG 40 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG passwordMinLength: 2020-06-17T10:11:07Z DEBUG 8 2020-06-17T10:11:07Z DEBUG passwordMinDigits: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinAlphas: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinUppers: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinLowers: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinSpecials: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMin8bit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxRepeats: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinCategories: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG passwordMinTokenLength: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG passwordPalindrome: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordDictCheck: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordDictPath: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordUserAttributes: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordBadWords: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordMaxSequence: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxSeqSets: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxClassChars: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-schemacheck: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-schemamod: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-schemareplace: 2020-06-17T10:11:07Z DEBUG replication-only 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 500 2020-06-17T10:11:07Z DEBUG passwordMaxFailure: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:11:07Z DEBUG nsslapd-lastmod: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-security: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordMaxAge: 2020-06-17T10:11:07Z DEBUG 8640000 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG passwordResetFailureCount: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordLegacyPolicy: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-rootpw: 2020-06-17T10:11:07Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:11:07Z DEBUG passwordChange: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:11:07Z DEBUG 256 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG nsslapd-securePort: 2020-06-17T10:11:07Z DEBUG 636 2020-06-17T10:11:07Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-timelimit: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:11:07Z DEBUG 64 2020-06-17T10:11:07Z DEBUG nsslapd-svrtab: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordExp: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordSendExpiringTime: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG day 2020-06-17T10:11:07Z DEBUG passwordLockoutDuration: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-idletimeout: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-nagle: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-csnlogging: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordCheckSyntax: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-listenhost: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-snmp-index: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:11:07Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:11:07Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:11:07Z DEBUG cn=Directory Manager 2020-06-17T10:11:07Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:11:07Z DEBUG uidNumber 2020-06-17T10:11:07Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:11:07Z DEBUG gidNumber 2020-06-17T10:11:07Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:11:07Z DEBUG dc=example,dc=com 2020-06-17T10:11:07Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:11:07Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-counters: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-rootdn: 2020-06-17T10:11:07Z DEBUG cn=Directory Manager 2020-06-17T10:11:07Z DEBUG passwordMinAge: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:11:07Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-result-tweak: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-maxbersize: 2020-06-17T10:11:07Z DEBUG 209715200 2020-06-17T10:11:07Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-versionstring: 2020-06-17T10:11:07Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:11:07Z DEBUG nsslapd-referralmode: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:11:07Z DEBUG 262144 2020-06-17T10:11:07Z DEBUG nsslapd-conntablesize: 2020-06-17T10:11:07Z DEBUG 1024 2020-06-17T10:11:07Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:11:07Z DEBUG allowed 2020-06-17T10:11:07Z DEBUG nsslapd-config: 2020-06-17T10:11:07Z DEBUG cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-instancedir: 2020-06-17T10:11:07Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-schemadir: 2020-06-17T10:11:07Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:11:07Z DEBUG nsslapd-lockdir: 2020-06-17T10:11:07Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-tmpdir: 2020-06-17T10:11:07Z DEBUG /tmp 2020-06-17T10:11:07Z DEBUG nsslapd-certdir: 2020-06-17T10:11:07Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-ldifdir: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:11:07Z DEBUG nsslapd-bakdir: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:11:07Z DEBUG nsslapd-saslpath: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-rundir: 2020-06-17T10:11:07Z DEBUG /var/run/dirsrv 2020-06-17T10:11:07Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:11:07Z DEBUG 300000 2020-06-17T10:11:07Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-localssf: 2020-06-17T10:11:07Z DEBUG 71 2020-06-17T10:11:07Z DEBUG nsslapd-minssf: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:11:07Z DEBUG next 2020-06-17T10:11:07Z DEBUG nsslapd-validate-cert: 2020-06-17T10:11:07Z DEBUG warn 2020-06-17T10:11:07Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:11:07Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:11:07Z DEBUG 60 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:11:07Z DEBUG 20971520 2020-06-17T10:11:07Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:11:07Z DEBUG nolog 2020-06-17T10:11:07Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:11:07Z DEBUG 128 2020-06-17T10:11:07Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:11:07Z DEBUG -1 2020-06-17T10:11:07Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:11:07Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-logging-backend: 2020-06-17T10:11:07Z DEBUG dirsrv-log 2020-06-17T10:11:07Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:11:07Z DEBUG none 2020-06-17T10:11:07Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:11:07Z DEBUG warn-invalid 2020-06-17T10:11:07Z DEBUG passwordStorageScheme: 2020-06-17T10:11:07Z DEBUG PBKDF2_SHA256 2020-06-17T10:11:07Z DEBUG passwordAdminDN: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:11:07Z DEBUG PBKDF2_SHA256 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-hash-filters: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:11:07Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG add: '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG add: updated value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=config 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG config 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG nsslapdConfig 2020-06-17T10:11:07Z DEBUG nsslapd-backendconfig: 2020-06-17T10:11:07Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-betype: 2020-06-17T10:11:07Z DEBUG ldbm database 2020-06-17T10:11:07Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:11:07Z DEBUG cn=schema 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG cn=monitor 2020-06-17T10:11:07Z DEBUG cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-plugin: 2020-06-17T10:11:07Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-port 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 10 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:11:07Z DEBUG 16384 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-port: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-workingdir: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-localuser: 2020-06-17T10:11:07Z DEBUG dirsrv 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG passwordInHistory: 2020-06-17T10:11:07Z DEBUG 6 2020-06-17T10:11:07Z DEBUG passwordUnlock: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordGraceLimit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG passwordMustChange: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-sizelimit: 2020-06-17T10:11:07Z DEBUG 2000 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG passwordWarning: 2020-06-17T10:11:07Z DEBUG 86400 2020-06-17T10:11:07Z DEBUG nsslapd-readonly: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-threadnumber: 2020-06-17T10:11:07Z DEBUG 16 2020-06-17T10:11:07Z DEBUG passwordLockout: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-localhost: 2020-06-17T10:11:07Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:11:07Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:11:07Z DEBUG 10000 2020-06-17T10:11:07Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:11:07Z DEBUG 40 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG passwordMinLength: 2020-06-17T10:11:07Z DEBUG 8 2020-06-17T10:11:07Z DEBUG passwordMinDigits: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinAlphas: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinUppers: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinLowers: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinSpecials: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMin8bit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxRepeats: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinCategories: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG passwordMinTokenLength: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG passwordPalindrome: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordDictCheck: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordDictPath: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordUserAttributes: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordBadWords: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordMaxSequence: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxSeqSets: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxClassChars: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-schemacheck: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-schemamod: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-schemareplace: 2020-06-17T10:11:07Z DEBUG replication-only 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 500 2020-06-17T10:11:07Z DEBUG passwordMaxFailure: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:11:07Z DEBUG nsslapd-lastmod: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-security: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordMaxAge: 2020-06-17T10:11:07Z DEBUG 8640000 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG passwordResetFailureCount: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordLegacyPolicy: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-rootpw: 2020-06-17T10:11:07Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:11:07Z DEBUG passwordChange: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:11:07Z DEBUG 256 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG nsslapd-securePort: 2020-06-17T10:11:07Z DEBUG 636 2020-06-17T10:11:07Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-timelimit: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:11:07Z DEBUG 64 2020-06-17T10:11:07Z DEBUG nsslapd-svrtab: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordExp: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordSendExpiringTime: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG day 2020-06-17T10:11:07Z DEBUG passwordLockoutDuration: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-idletimeout: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-nagle: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-csnlogging: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordCheckSyntax: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-listenhost: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-snmp-index: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:11:07Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:11:07Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:11:07Z DEBUG cn=Directory Manager 2020-06-17T10:11:07Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:11:07Z DEBUG uidNumber 2020-06-17T10:11:07Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:11:07Z DEBUG gidNumber 2020-06-17T10:11:07Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:11:07Z DEBUG dc=example,dc=com 2020-06-17T10:11:07Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:11:07Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-counters: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-rootdn: 2020-06-17T10:11:07Z DEBUG cn=Directory Manager 2020-06-17T10:11:07Z DEBUG passwordMinAge: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:11:07Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-result-tweak: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-maxbersize: 2020-06-17T10:11:07Z DEBUG 209715200 2020-06-17T10:11:07Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-versionstring: 2020-06-17T10:11:07Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:11:07Z DEBUG nsslapd-referralmode: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:11:07Z DEBUG 262144 2020-06-17T10:11:07Z DEBUG nsslapd-conntablesize: 2020-06-17T10:11:07Z DEBUG 1024 2020-06-17T10:11:07Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:11:07Z DEBUG allowed 2020-06-17T10:11:07Z DEBUG nsslapd-config: 2020-06-17T10:11:07Z DEBUG cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-instancedir: 2020-06-17T10:11:07Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-schemadir: 2020-06-17T10:11:07Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:11:07Z DEBUG nsslapd-lockdir: 2020-06-17T10:11:07Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-tmpdir: 2020-06-17T10:11:07Z DEBUG /tmp 2020-06-17T10:11:07Z DEBUG nsslapd-certdir: 2020-06-17T10:11:07Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-ldifdir: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:11:07Z DEBUG nsslapd-bakdir: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:11:07Z DEBUG nsslapd-saslpath: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-rundir: 2020-06-17T10:11:07Z DEBUG /var/run/dirsrv 2020-06-17T10:11:07Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:11:07Z DEBUG 300000 2020-06-17T10:11:07Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-localssf: 2020-06-17T10:11:07Z DEBUG 71 2020-06-17T10:11:07Z DEBUG nsslapd-minssf: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:11:07Z DEBUG next 2020-06-17T10:11:07Z DEBUG nsslapd-validate-cert: 2020-06-17T10:11:07Z DEBUG warn 2020-06-17T10:11:07Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:11:07Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:11:07Z DEBUG 60 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:11:07Z DEBUG 20971520 2020-06-17T10:11:07Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:11:07Z DEBUG nolog 2020-06-17T10:11:07Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:11:07Z DEBUG 128 2020-06-17T10:11:07Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:11:07Z DEBUG -1 2020-06-17T10:11:07Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:11:07Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-logging-backend: 2020-06-17T10:11:07Z DEBUG dirsrv-log 2020-06-17T10:11:07Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:11:07Z DEBUG none 2020-06-17T10:11:07Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:11:07Z DEBUG warn-invalid 2020-06-17T10:11:07Z DEBUG passwordStorageScheme: 2020-06-17T10:11:07Z DEBUG PBKDF2_SHA256 2020-06-17T10:11:07Z DEBUG passwordAdminDN: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:11:07Z DEBUG PBKDF2_SHA256 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-hash-filters: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:11:07Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG [(0, 'aci', ['(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:11:07Z DEBUG Updated 1 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG New entry: cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG ipapermission 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Add Configuration Sub-Entries 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG ipapermissiontype: 2020-06-17T10:11:07Z DEBUG SYSTEM 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG ipapermission 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Add Configuration Sub-Entries 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG ipapermissiontype: 2020-06-17T10:11:07Z DEBUG SYSTEM 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=config 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=config 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG config 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG nsslapdConfig 2020-06-17T10:11:07Z DEBUG nsslapd-backendconfig: 2020-06-17T10:11:07Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-betype: 2020-06-17T10:11:07Z DEBUG ldbm database 2020-06-17T10:11:07Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:11:07Z DEBUG cn=schema 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG cn=monitor 2020-06-17T10:11:07Z DEBUG cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-plugin: 2020-06-17T10:11:07Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-port 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 10 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:11:07Z DEBUG 16384 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-port: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-workingdir: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-localuser: 2020-06-17T10:11:07Z DEBUG dirsrv 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG passwordInHistory: 2020-06-17T10:11:07Z DEBUG 6 2020-06-17T10:11:07Z DEBUG passwordUnlock: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordGraceLimit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG passwordMustChange: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-sizelimit: 2020-06-17T10:11:07Z DEBUG 2000 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG passwordWarning: 2020-06-17T10:11:07Z DEBUG 86400 2020-06-17T10:11:07Z DEBUG nsslapd-readonly: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-threadnumber: 2020-06-17T10:11:07Z DEBUG 16 2020-06-17T10:11:07Z DEBUG passwordLockout: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-localhost: 2020-06-17T10:11:07Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:11:07Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:11:07Z DEBUG 10000 2020-06-17T10:11:07Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:11:07Z DEBUG 40 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG passwordMinLength: 2020-06-17T10:11:07Z DEBUG 8 2020-06-17T10:11:07Z DEBUG passwordMinDigits: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinAlphas: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinUppers: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinLowers: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinSpecials: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMin8bit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxRepeats: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinCategories: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG passwordMinTokenLength: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG passwordPalindrome: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordDictCheck: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordDictPath: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordUserAttributes: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordBadWords: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordMaxSequence: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxSeqSets: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxClassChars: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-schemacheck: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-schemamod: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-schemareplace: 2020-06-17T10:11:07Z DEBUG replication-only 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 500 2020-06-17T10:11:07Z DEBUG passwordMaxFailure: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:11:07Z DEBUG nsslapd-lastmod: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-security: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordMaxAge: 2020-06-17T10:11:07Z DEBUG 8640000 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG passwordResetFailureCount: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordLegacyPolicy: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-rootpw: 2020-06-17T10:11:07Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:11:07Z DEBUG passwordChange: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:11:07Z DEBUG 256 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG nsslapd-securePort: 2020-06-17T10:11:07Z DEBUG 636 2020-06-17T10:11:07Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-timelimit: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:11:07Z DEBUG 64 2020-06-17T10:11:07Z DEBUG nsslapd-svrtab: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordExp: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordSendExpiringTime: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG day 2020-06-17T10:11:07Z DEBUG passwordLockoutDuration: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-idletimeout: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-nagle: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-csnlogging: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordCheckSyntax: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-listenhost: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-snmp-index: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:11:07Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:11:07Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:11:07Z DEBUG cn=Directory Manager 2020-06-17T10:11:07Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:11:07Z DEBUG uidNumber 2020-06-17T10:11:07Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:11:07Z DEBUG gidNumber 2020-06-17T10:11:07Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:11:07Z DEBUG dc=example,dc=com 2020-06-17T10:11:07Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:11:07Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-counters: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-rootdn: 2020-06-17T10:11:07Z DEBUG cn=Directory Manager 2020-06-17T10:11:07Z DEBUG passwordMinAge: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:11:07Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-result-tweak: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-maxbersize: 2020-06-17T10:11:07Z DEBUG 209715200 2020-06-17T10:11:07Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-versionstring: 2020-06-17T10:11:07Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:11:07Z DEBUG nsslapd-referralmode: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:11:07Z DEBUG 262144 2020-06-17T10:11:07Z DEBUG nsslapd-conntablesize: 2020-06-17T10:11:07Z DEBUG 1024 2020-06-17T10:11:07Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:11:07Z DEBUG allowed 2020-06-17T10:11:07Z DEBUG nsslapd-config: 2020-06-17T10:11:07Z DEBUG cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-instancedir: 2020-06-17T10:11:07Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-schemadir: 2020-06-17T10:11:07Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:11:07Z DEBUG nsslapd-lockdir: 2020-06-17T10:11:07Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-tmpdir: 2020-06-17T10:11:07Z DEBUG /tmp 2020-06-17T10:11:07Z DEBUG nsslapd-certdir: 2020-06-17T10:11:07Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-ldifdir: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:11:07Z DEBUG nsslapd-bakdir: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:11:07Z DEBUG nsslapd-saslpath: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-rundir: 2020-06-17T10:11:07Z DEBUG /var/run/dirsrv 2020-06-17T10:11:07Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:11:07Z DEBUG 300000 2020-06-17T10:11:07Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-localssf: 2020-06-17T10:11:07Z DEBUG 71 2020-06-17T10:11:07Z DEBUG nsslapd-minssf: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:11:07Z DEBUG next 2020-06-17T10:11:07Z DEBUG nsslapd-validate-cert: 2020-06-17T10:11:07Z DEBUG warn 2020-06-17T10:11:07Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:11:07Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:11:07Z DEBUG 60 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:11:07Z DEBUG 20971520 2020-06-17T10:11:07Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:11:07Z DEBUG nolog 2020-06-17T10:11:07Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:11:07Z DEBUG 128 2020-06-17T10:11:07Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:11:07Z DEBUG -1 2020-06-17T10:11:07Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:11:07Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-logging-backend: 2020-06-17T10:11:07Z DEBUG dirsrv-log 2020-06-17T10:11:07Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:11:07Z DEBUG none 2020-06-17T10:11:07Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:11:07Z DEBUG warn-invalid 2020-06-17T10:11:07Z DEBUG passwordStorageScheme: 2020-06-17T10:11:07Z DEBUG PBKDF2_SHA256 2020-06-17T10:11:07Z DEBUG passwordAdminDN: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:11:07Z DEBUG PBKDF2_SHA256 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-hash-filters: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:11:07Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG add: '(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG add: updated value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=config 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG config 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG nsslapdConfig 2020-06-17T10:11:07Z DEBUG nsslapd-backendconfig: 2020-06-17T10:11:07Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-betype: 2020-06-17T10:11:07Z DEBUG ldbm database 2020-06-17T10:11:07Z DEBUG nsslapd-privatenamespaces: 2020-06-17T10:11:07Z DEBUG cn=schema 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG cn=monitor 2020-06-17T10:11:07Z DEBUG cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-plugin: 2020-06-17T10:11:07Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-requiresrestart: 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-port 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-secureport 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-workingdir 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-plugin 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogdir 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-db-locks 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-17T10:11:07Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-17T10:11:07Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-17T10:11:07Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 10 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-level: 2020-06-17T10:11:07Z DEBUG 16384 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-port: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-workingdir: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-maxthreadsperconn: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-localuser: 2020-06-17T10:11:07Z DEBUG dirsrv 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG passwordInHistory: 2020-06-17T10:11:07Z DEBUG 6 2020-06-17T10:11:07Z DEBUG passwordUnlock: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordGraceLimit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG passwordMustChange: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-pwpolicy-local: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-sizelimit: 2020-06-17T10:11:07Z DEBUG 2000 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG passwordWarning: 2020-06-17T10:11:07Z DEBUG 86400 2020-06-17T10:11:07Z DEBUG nsslapd-readonly: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-threadnumber: 2020-06-17T10:11:07Z DEBUG 16 2020-06-17T10:11:07Z DEBUG passwordLockout: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-enquote-sup-oc: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-localhost: 2020-06-17T10:11:07Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:11:07Z DEBUG nsslapd-ioblocktimeout: 2020-06-17T10:11:07Z DEBUG 10000 2020-06-17T10:11:07Z DEBUG nsslapd-max-filter-nest-level: 2020-06-17T10:11:07Z DEBUG 40 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG passwordMinLength: 2020-06-17T10:11:07Z DEBUG 8 2020-06-17T10:11:07Z DEBUG passwordMinDigits: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinAlphas: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinUppers: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinLowers: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinSpecials: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMin8bit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxRepeats: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMinCategories: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG passwordMinTokenLength: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG passwordPalindrome: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordDictCheck: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordDictPath: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordUserAttributes: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordBadWords: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordMaxSequence: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxSeqSets: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG passwordMaxClassChars: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/errors 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-schemacheck: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-schemamod: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-syntaxcheck: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-syntaxlogging: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-dn-validate-strict: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-schemareplace: 2020-06-17T10:11:07Z DEBUG replication-only 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 500 2020-06-17T10:11:07Z DEBUG passwordMaxFailure: 2020-06-17T10:11:07Z DEBUG 3 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/access 2020-06-17T10:11:07Z DEBUG nsslapd-lastmod: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-security: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordMaxAge: 2020-06-17T10:11:07Z DEBUG 8640000 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG passwordResetFailureCount: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG passwordIsGlobalPolicy: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordLegacyPolicy: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordTrackUpdateTime: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-groupevalnestlevel: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-rootpw: 2020-06-17T10:11:07Z DEBUG {PBKDF2_SHA256}AAAIALruUDGW3nhQ2Ryrjlz3ImPq9D16mYcR4iWVdLaqRONRM4I3bUa+vfT2c8NELLVZNcrLuBFqpX1+CIehlCXnBc69O4is/aHHJfLXvW4fNcUMoiuEFCfbB8Rbx7R7HIgmtKjR1EqWyZ4Fa0zcCAXRgL/Eq9/ab1xoqts38rCdrDmuk9p5VEG/zxsv7L2S5cVlTbaMPb44nprp4We5XiLjM6utJpU1mojcPOnKeTIkhWWQhJ9XIxGsEHPI9EOP5LMxGJuTM2WbVYZtocy7ppyb17V9erHulE7ZL1XD4QqXzRhWOLYySlSDNNYfkwjseVhPp+tQ+nI7tVynvnqc/l53l8Oc5u+G7APhZYdOSCB9MWi0chCGV0DiRuM4Y3urk6DM9glzm1dJmOqhGMqvW3UhQFcaNPTfjK7pBBkfMGLEThyd 2020-06-17T10:11:07Z DEBUG passwordChange: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-level: 2020-06-17T10:11:07Z DEBUG 256 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG nsslapd-securePort: 2020-06-17T10:11:07Z DEBUG 636 2020-06-17T10:11:07Z DEBUG nsslapd-certmap-basedn: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-timelimit: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-reservedescriptors: 2020-06-17T10:11:07Z DEBUG 64 2020-06-17T10:11:07Z DEBUG nsslapd-svrtab: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG passwordExp: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG passwordSendExpiringTime: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-accesscontrol: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG day 2020-06-17T10:11:07Z DEBUG passwordLockoutDuration: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-idletimeout: 2020-06-17T10:11:07Z DEBUG 3600 2020-06-17T10:11:07Z DEBUG nsslapd-nagle: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-csnlogging: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG passwordCheckSyntax: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-listenhost: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-snmp-index: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-ldapifilepath: 2020-06-17T10:11:07Z DEBUG /var/run/slapd-LIN-TEST-LAN.socket 2020-06-17T10:11:07Z DEBUG nsslapd-ldapilisten: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapiautobind: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapimaprootdn: 2020-06-17T10:11:07Z DEBUG cn=Directory Manager 2020-06-17T10:11:07Z DEBUG nsslapd-ldapimaptoentries: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-17T10:11:07Z DEBUG uidNumber 2020-06-17T10:11:07Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-17T10:11:07Z DEBUG gidNumber 2020-06-17T10:11:07Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-17T10:11:07Z DEBUG dc=example,dc=com 2020-06-17T10:11:07Z DEBUG nsslapd-anonlimitsdn: 2020-06-17T10:11:07Z DEBUG cn=anonymous-limits,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-counters: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-securelistenhost: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-rootdn: 2020-06-17T10:11:07Z DEBUG cn=Directory Manager 2020-06-17T10:11:07Z DEBUG passwordMinAge: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:11:07Z DEBUG nsslapd-return-exact-case: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-result-tweak: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-moddn-aci: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-maxbersize: 2020-06-17T10:11:07Z DEBUG 209715200 2020-06-17T10:11:07Z DEBUG nsslapd-maxsasliosize: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-versionstring: 2020-06-17T10:11:07Z DEBUG 389-Directory/1.4.2.4 2020-06-17T10:11:07Z DEBUG nsslapd-referralmode: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-maxdescriptors: 2020-06-17T10:11:07Z DEBUG 262144 2020-06-17T10:11:07Z DEBUG nsslapd-conntablesize: 2020-06-17T10:11:07Z DEBUG 1024 2020-06-17T10:11:07Z DEBUG nsslapd-SSLclientAuth: 2020-06-17T10:11:07Z DEBUG allowed 2020-06-17T10:11:07Z DEBUG nsslapd-config: 2020-06-17T10:11:07Z DEBUG cn=config 2020-06-17T10:11:07Z DEBUG nsslapd-instancedir: 2020-06-17T10:11:07Z DEBUG /usr/lib64/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-schemadir: 2020-06-17T10:11:07Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN/schema 2020-06-17T10:11:07Z DEBUG nsslapd-lockdir: 2020-06-17T10:11:07Z DEBUG /var/lock/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-tmpdir: 2020-06-17T10:11:07Z DEBUG /tmp 2020-06-17T10:11:07Z DEBUG nsslapd-certdir: 2020-06-17T10:11:07Z DEBUG /etc/dirsrv/slapd-LIN-TEST-LAN 2020-06-17T10:11:07Z DEBUG nsslapd-ldifdir: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/ldif 2020-06-17T10:11:07Z DEBUG nsslapd-bakdir: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/bak 2020-06-17T10:11:07Z DEBUG nsslapd-saslpath: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-rundir: 2020-06-17T10:11:07Z DEBUG /var/run/dirsrv 2020-06-17T10:11:07Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-17T10:11:07Z DEBUG 300000 2020-06-17T10:11:07Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-require-secure-binds: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-allow-anonymous-access: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-localssf: 2020-06-17T10:11:07Z DEBUG 71 2020-06-17T10:11:07Z DEBUG nsslapd-minssf: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-force-sasl-external: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-entryusn-global: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-entryusn-import-initval: 2020-06-17T10:11:07Z DEBUG next 2020-06-17T10:11:07Z DEBUG nsslapd-validate-cert: 2020-06-17T10:11:07Z DEBUG warn 2020-06-17T10:11:07Z DEBUG nsslapd-pagedsizelimit: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-defaultnamingcontext: 2020-06-17T10:11:07Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-17T10:11:07Z DEBUG 60 2020-06-17T10:11:07Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-17T10:11:07Z DEBUG 20971520 2020-06-17T10:11:07Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-17T10:11:07Z DEBUG nolog 2020-06-17T10:11:07Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-17T10:11:07Z DEBUG 2097152 2020-06-17T10:11:07Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-enable-turbo-mode: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-connection-buffer: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-connection-nocanon: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-logging: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-listen-backlog-size: 2020-06-17T10:11:07Z DEBUG 128 2020-06-17T10:11:07Z DEBUG nsslapd-dynamic-plugins: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-mxfast: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-17T10:11:07Z DEBUG -10 2020-06-17T10:11:07Z DEBUG nsslapd-ignore-time-skew: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-global-backend-lock: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-17T10:11:07Z DEBUG -1 2020-06-17T10:11:07Z DEBUG nsslapd-enable-nunc-stans: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-mode: 2020-06-17T10:11:07Z DEBUG 600 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-17T10:11:07Z DEBUG 0 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-17T10:11:07Z DEBUG 1 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-17T10:11:07Z DEBUG 2 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-17T10:11:07Z DEBUG month 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-17T10:11:07Z DEBUG 5 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-17T10:11:07Z DEBUG week 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog: 2020-06-17T10:11:07Z DEBUG /var/log/dirsrv/slapd-LIN-TEST-LAN/audit 2020-06-17T10:11:07Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-extract-pemfiles: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-logging-backend: 2020-06-17T10:11:07Z DEBUG dirsrv-log 2020-06-17T10:11:07Z DEBUG nsslapd-tls-check-crl: 2020-06-17T10:11:07Z DEBUG none 2020-06-17T10:11:07Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-verify-filter-schema: 2020-06-17T10:11:07Z DEBUG warn-invalid 2020-06-17T10:11:07Z DEBUG passwordStorageScheme: 2020-06-17T10:11:07Z DEBUG PBKDF2_SHA256 2020-06-17T10:11:07Z DEBUG passwordAdminDN: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-17T10:11:07Z DEBUG PBKDF2_SHA256 2020-06-17T10:11:07Z DEBUG nsslapd-errorlog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-accesslog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-auditlog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG nsslapd-ssl-check-hostname: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-hash-filters: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-auditfaillog-list: 2020-06-17T10:11:07Z DEBUG 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-17T10:11:07Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG [(0, 'aci', ['(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:11:07Z DEBUG Updated 1 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG New entry: cn=CA Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=CA Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG CA Administrator 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG CA Administrator 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=CA Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG CA Administrator 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG CA Administrator 2020-06-17T10:11:07Z DEBUG New entry: cn=Vault Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Vault Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Vault Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Vault Administrators 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Vault Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Vault Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Vault Administrators 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=DNS Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=DNS Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG DNS Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG DNS Administrators 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=DNS Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG DNS Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG DNS Administrators 2020-06-17T10:11:07Z DEBUG [] 2020-06-17T10:11:07Z DEBUG Updated 0 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=DNS Servers,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=DNS Servers,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG DNS Servers 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG DNS Servers 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=DNS Servers,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG DNS Servers 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG DNS Servers 2020-06-17T10:11:07Z DEBUG [] 2020-06-17T10:11:07Z DEBUG Updated 0 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-delegation.update 0.839 sec 2020-06-17T10:11:07Z DEBUG Parsing update file '/usr/share/ipa/updates/40-dns.update' 2020-06-17T10:11:07Z DEBUG New entry: cn=dns,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=dns,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG addifexist: 'idnsConfigObject' to objectClass, current value [] 2020-06-17T10:11:07Z DEBUG addifexist: '(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)' to aci, current value [] 2020-06-17T10:11:07Z DEBUG addifexist: '(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)' to aci, current value [] 2020-06-17T10:11:07Z DEBUG addifexist: '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' to aci, current value [] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=dns,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG New entry: cn=dns,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=dns,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG replace: (targetattr = "*")(version 3.0; acl "No access to DNS tree without a permission"; deny (read,search,compare) (groupdn != "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan") and (groupdn != "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan");) not found, skipping 2020-06-17T10:11:07Z DEBUG replace: (targetattr = "*")(version 3.0; acl "Allow read access"; allow (read,search,compare) groupdn = "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan" or userattr = "parent[0,1].managedby#GROUPDN";) not found, skipping 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=dns,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG New entry: cn=dns,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=dns,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders")(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [] 2020-06-17T10:11:07Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders")(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2020-06-17T10:11:07Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord ")(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [] 2020-06-17T10:11:07Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord ")(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2020-06-17T10:11:07Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [] 2020-06-17T10:11:07Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2020-06-17T10:11:07Z DEBUG remove: '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [] 2020-06-17T10:11:07Z DEBUG remove: '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=dns,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=IPA DNS,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=IPA DNS,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG IPA DNS 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:07Z DEBUG database 2020-06-17T10:11:07Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:07Z DEBUG IPA DNS support plugin 2020-06-17T10:11:07Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:07Z DEBUG ipa_dns 2020-06-17T10:11:07Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:07Z DEBUG ipadns_init 2020-06-17T10:11:07Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:07Z DEBUG libipa_dns.so 2020-06-17T10:11:07Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:07Z DEBUG preoperation 2020-06-17T10:11:07Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:07Z DEBUG Red Hat, Inc. 2020-06-17T10:11:07Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:07Z DEBUG 1.0 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG nsslapdPlugin 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=IPA DNS,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG IPA DNS 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:07Z DEBUG database 2020-06-17T10:11:07Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:07Z DEBUG IPA DNS support plugin 2020-06-17T10:11:07Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:07Z DEBUG ipa_dns 2020-06-17T10:11:07Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:07Z DEBUG ipadns_init 2020-06-17T10:11:07Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:07Z DEBUG libipa_dns.so 2020-06-17T10:11:07Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:07Z DEBUG preoperation 2020-06-17T10:11:07Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:07Z DEBUG Red Hat, Inc. 2020-06-17T10:11:07Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:07Z DEBUG 1.0 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG nsslapdPlugin 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG [] 2020-06-17T10:11:07Z DEBUG Updated 0 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-dns.update 0.009 sec 2020-06-17T10:11:07Z DEBUG Parsing update file '/usr/share/ipa/updates/40-otp.update' 2020-06-17T10:11:07Z DEBUG New entry: cn=otp,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=otp,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG otp 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=otp,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG otp 2020-06-17T10:11:07Z DEBUG New entry: cn=otp,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=otp,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG ipatokenOTPConfig 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG otp 2020-06-17T10:11:07Z DEBUG ipatokenTOTPauthWindow: 2020-06-17T10:11:07Z DEBUG 300 2020-06-17T10:11:07Z DEBUG ipatokenTOTPsyncWindow: 2020-06-17T10:11:07Z DEBUG 86400 2020-06-17T10:11:07Z DEBUG ipatokenHOTPauthWindow: 2020-06-17T10:11:07Z DEBUG 10 2020-06-17T10:11:07Z DEBUG ipatokenHOTPsyncWindow: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=otp,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG ipatokenOTPConfig 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG otp 2020-06-17T10:11:07Z DEBUG ipatokenTOTPauthWindow: 2020-06-17T10:11:07Z DEBUG 300 2020-06-17T10:11:07Z DEBUG ipatokenTOTPsyncWindow: 2020-06-17T10:11:07Z DEBUG 86400 2020-06-17T10:11:07Z DEBUG ipatokenHOTPauthWindow: 2020-06-17T10:11:07Z DEBUG 10 2020-06-17T10:11:07Z DEBUG ipatokenHOTPsyncWindow: 2020-06-17T10:11:07Z DEBUG 100 2020-06-17T10:11:07Z DEBUG Updating existing entry: dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG domain 2020-06-17T10:11:07Z DEBUG pilotObject 2020-06-17T10:11:07Z DEBUG domainRelatedObject 2020-06-17T10:11:07Z DEBUG nisDomainObject 2020-06-17T10:11:07Z DEBUG dc: 2020-06-17T10:11:07Z DEBUG lin 2020-06-17T10:11:07Z DEBUG info: 2020-06-17T10:11:07Z DEBUG IPA V2.0 2020-06-17T10:11:07Z DEBUG nisDomain: 2020-06-17T10:11:07Z DEBUG lin.test.lan 2020-06-17T10:11:07Z DEBUG associatedDomain: 2020-06-17T10:11:07Z DEBUG lin.test.lan 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:11:07Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:07Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:07Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:11:07Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:11:07Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:07Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:07Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:11:07Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:07Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG remove: '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create and delete tokens"; allow (add, delete) userattr = "ipatokenOwner#SELFDN";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG remove: '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create and delete tokens"; allow (add, delete) userattr = "ipatokenOwner#SELFDN";)' not in aci 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN";)' not in aci 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can write basic token info"; allow (write) userattr = "ipatokenOwner#USERDN";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can write basic token info"; allow (write) userattr = "ipatokenOwner#USERDN";)' not in aci 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPclockOffset || ipatokenTOTPtimeStep")(version 3.0; acl "Users can add TOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPclockOffset || ipatokenTOTPtimeStep")(version 3.0; acl "Users can add TOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' not in aci 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenHOTPcounter")(version 3.0; acl "Users can add HOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenHOTPcounter")(version 3.0; acl "Users can add HOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' not in aci 2020-06-17T10:11:07Z DEBUG add: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2020-06-17T10:11:07Z DEBUG add: '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2020-06-17T10:11:07Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2020-06-17T10:11:07Z DEBUG add: '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2020-06-17T10:11:07Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2020-06-17T10:11:07Z DEBUG add: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2020-06-17T10:11:07Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)'] 2020-06-17T10:11:07Z DEBUG add: '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)'] 2020-06-17T10:11:07Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)'] 2020-06-17T10:11:07Z DEBUG add: '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)'] 2020-06-17T10:11:07Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG domain 2020-06-17T10:11:07Z DEBUG pilotObject 2020-06-17T10:11:07Z DEBUG domainRelatedObject 2020-06-17T10:11:07Z DEBUG nisDomainObject 2020-06-17T10:11:07Z DEBUG dc: 2020-06-17T10:11:07Z DEBUG lin 2020-06-17T10:11:07Z DEBUG info: 2020-06-17T10:11:07Z DEBUG IPA V2.0 2020-06-17T10:11:07Z DEBUG nisDomain: 2020-06-17T10:11:07Z DEBUG lin.test.lan 2020-06-17T10:11:07Z DEBUG associatedDomain: 2020-06-17T10:11:07Z DEBUG lin.test.lan 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:11:07Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:07Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:07Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:07Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:07Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:07Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:11:07Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:07Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:11:07Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:11:07Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:11:07Z DEBUG [] 2020-06-17T10:11:07Z DEBUG Updated 0 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG New entry: cn=radiusproxy,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=radiusproxy,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG radiusproxy 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=radiusproxy,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG radiusproxy 2020-06-17T10:11:07Z DEBUG New entry: cn=IPA OTP Last Token,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=IPA OTP Last Token,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG objectclass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG nsSlapdPlugin 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG IPA OTP Last Token 2020-06-17T10:11:07Z DEBUG nsslapd-pluginpath: 2020-06-17T10:11:07Z DEBUG libipa_otp_lasttoken 2020-06-17T10:11:07Z DEBUG nsslapd-plugininitfunc: 2020-06-17T10:11:07Z DEBUG ipa_otp_lasttoken_init 2020-06-17T10:11:07Z DEBUG nsslapd-plugintype: 2020-06-17T10:11:07Z DEBUG preoperation 2020-06-17T10:11:07Z DEBUG nsslapd-pluginenabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-pluginid: 2020-06-17T10:11:07Z DEBUG ipa-otp-lasttoken 2020-06-17T10:11:07Z DEBUG nsslapd-pluginversion: 2020-06-17T10:11:07Z DEBUG 1.0 2020-06-17T10:11:07Z DEBUG nsslapd-pluginvendor: 2020-06-17T10:11:07Z DEBUG Red Hat, Inc. 2020-06-17T10:11:07Z DEBUG nsslapd-plugindescription: 2020-06-17T10:11:07Z DEBUG IPA OTP Last Token plugin 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:07Z DEBUG database 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=IPA OTP Last Token,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG objectclass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG nsSlapdPlugin 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG IPA OTP Last Token 2020-06-17T10:11:07Z DEBUG nsslapd-pluginpath: 2020-06-17T10:11:07Z DEBUG libipa_otp_lasttoken 2020-06-17T10:11:07Z DEBUG nsslapd-plugininitfunc: 2020-06-17T10:11:07Z DEBUG ipa_otp_lasttoken_init 2020-06-17T10:11:07Z DEBUG nsslapd-plugintype: 2020-06-17T10:11:07Z DEBUG preoperation 2020-06-17T10:11:07Z DEBUG nsslapd-pluginenabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-pluginid: 2020-06-17T10:11:07Z DEBUG ipa-otp-lasttoken 2020-06-17T10:11:07Z DEBUG nsslapd-pluginversion: 2020-06-17T10:11:07Z DEBUG 1.0 2020-06-17T10:11:07Z DEBUG nsslapd-pluginvendor: 2020-06-17T10:11:07Z DEBUG Red Hat, Inc. 2020-06-17T10:11:07Z DEBUG nsslapd-plugindescription: 2020-06-17T10:11:07Z DEBUG IPA OTP Last Token plugin 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:07Z DEBUG database 2020-06-17T10:11:07Z DEBUG New entry: cn=IPA OTP Counter,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=IPA OTP Counter,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG objectclass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG nsSlapdPlugin 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG IPA OTP Counter 2020-06-17T10:11:07Z DEBUG nsslapd-pluginpath: 2020-06-17T10:11:07Z DEBUG libipa_otp_counter 2020-06-17T10:11:07Z DEBUG nsslapd-plugininitfunc: 2020-06-17T10:11:07Z DEBUG ipa_otp_counter_init 2020-06-17T10:11:07Z DEBUG nsslapd-plugintype: 2020-06-17T10:11:07Z DEBUG preoperation 2020-06-17T10:11:07Z DEBUG nsslapd-pluginenabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-pluginid: 2020-06-17T10:11:07Z DEBUG ipa-otp-counter 2020-06-17T10:11:07Z DEBUG nsslapd-pluginversion: 2020-06-17T10:11:07Z DEBUG 1.0 2020-06-17T10:11:07Z DEBUG nsslapd-pluginvendor: 2020-06-17T10:11:07Z DEBUG Red Hat, Inc. 2020-06-17T10:11:07Z DEBUG nsslapd-plugindescription: 2020-06-17T10:11:07Z DEBUG IPA OTP Counter plugin 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:07Z DEBUG database 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=IPA OTP Counter,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG objectclass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG nsSlapdPlugin 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG IPA OTP Counter 2020-06-17T10:11:07Z DEBUG nsslapd-pluginpath: 2020-06-17T10:11:07Z DEBUG libipa_otp_counter 2020-06-17T10:11:07Z DEBUG nsslapd-plugininitfunc: 2020-06-17T10:11:07Z DEBUG ipa_otp_counter_init 2020-06-17T10:11:07Z DEBUG nsslapd-plugintype: 2020-06-17T10:11:07Z DEBUG preoperation 2020-06-17T10:11:07Z DEBUG nsslapd-pluginenabled: 2020-06-17T10:11:07Z DEBUG on 2020-06-17T10:11:07Z DEBUG nsslapd-pluginid: 2020-06-17T10:11:07Z DEBUG ipa-otp-counter 2020-06-17T10:11:07Z DEBUG nsslapd-pluginversion: 2020-06-17T10:11:07Z DEBUG 1.0 2020-06-17T10:11:07Z DEBUG nsslapd-pluginvendor: 2020-06-17T10:11:07Z DEBUG Red Hat, Inc. 2020-06-17T10:11:07Z DEBUG nsslapd-plugindescription: 2020-06-17T10:11:07Z DEBUG IPA OTP Counter plugin 2020-06-17T10:11:07Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:07Z DEBUG database 2020-06-17T10:11:07Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-otp.update 0.063 sec 2020-06-17T10:11:07Z DEBUG Parsing update file '/usr/share/ipa/updates/40-realm_domains.update' 2020-06-17T10:11:07Z DEBUG New entry: cn=Realm Domains,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Realm Domains,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG domainRelatedObject 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Realm Domains 2020-06-17T10:11:07Z DEBUG associatedDomain: 2020-06-17T10:11:07Z DEBUG lin.test.lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Realm Domains,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG domainRelatedObject 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Realm Domains 2020-06-17T10:11:07Z DEBUG associatedDomain: 2020-06-17T10:11:07Z DEBUG lin.test.lan 2020-06-17T10:11:07Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-realm_domains.update 0.006 sec 2020-06-17T10:11:07Z DEBUG Parsing update file '/usr/share/ipa/updates/40-replication.update' 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG userRoot 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG nsBackendInstance 2020-06-17T10:11:07Z DEBUG nsslapd-suffix: 2020-06-17T10:11:07Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-cachesize: 2020-06-17T10:11:07Z DEBUG -1 2020-06-17T10:11:07Z DEBUG nsslapd-cachememsize: 2020-06-17T10:11:07Z DEBUG 67108864 2020-06-17T10:11:07Z DEBUG nsslapd-readonly: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-require-index: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-dncachememsize: 2020-06-17T10:11:07Z DEBUG 67108864 2020-06-17T10:11:07Z DEBUG nsslapd-directory: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/db/userRoot 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG add: '(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG add: updated value ['(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG userRoot 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG nsBackendInstance 2020-06-17T10:11:07Z DEBUG nsslapd-suffix: 2020-06-17T10:11:07Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG nsslapd-cachesize: 2020-06-17T10:11:07Z DEBUG -1 2020-06-17T10:11:07Z DEBUG nsslapd-cachememsize: 2020-06-17T10:11:07Z DEBUG 67108864 2020-06-17T10:11:07Z DEBUG nsslapd-readonly: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-require-index: 2020-06-17T10:11:07Z DEBUG off 2020-06-17T10:11:07Z DEBUG nsslapd-dncachememsize: 2020-06-17T10:11:07Z DEBUG 67108864 2020-06-17T10:11:07Z DEBUG nsslapd-directory: 2020-06-17T10:11:07Z DEBUG /var/lib/dirsrv/slapd-LIN-TEST-LAN/db/userRoot 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG [] 2020-06-17T10:11:07Z DEBUG Updated 0 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=Modify DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Modify DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG ipapermission 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Modify DNA Range 2020-06-17T10:11:07Z DEBUG ipaPermissionType: 2020-06-17T10:11:07Z DEBUG SYSTEM 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Modify DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG ipapermission 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Modify DNA Range 2020-06-17T10:11:07Z DEBUG ipaPermissionType: 2020-06-17T10:11:07Z DEBUG SYSTEM 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG [] 2020-06-17T10:11:07Z DEBUG Updated 0 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Posix IDs 2020-06-17T10:11:07Z DEBUG dnaExcludeScope: 2020-06-17T10:11:07Z DEBUG cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG dnaFilter: 2020-06-17T10:11:07Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2020-06-17T10:11:07Z DEBUG dnaMagicRegen: 2020-06-17T10:11:07Z DEBUG -1 2020-06-17T10:11:07Z DEBUG dnaMaxValue: 2020-06-17T10:11:07Z DEBUG 363799999 2020-06-17T10:11:07Z DEBUG dnaNextValue: 2020-06-17T10:11:07Z DEBUG 363600000 2020-06-17T10:11:07Z DEBUG dnaScope: 2020-06-17T10:11:07Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG dnaSharedCfgDN: 2020-06-17T10:11:07Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG dnaThreshold: 2020-06-17T10:11:07Z DEBUG 500 2020-06-17T10:11:07Z DEBUG dnaType: 2020-06-17T10:11:07Z DEBUG uidNumber 2020-06-17T10:11:07Z DEBUG gidNumber 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG add: '(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG add: updated value ['(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Posix IDs 2020-06-17T10:11:07Z DEBUG dnaExcludeScope: 2020-06-17T10:11:07Z DEBUG cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG dnaFilter: 2020-06-17T10:11:07Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2020-06-17T10:11:07Z DEBUG dnaMagicRegen: 2020-06-17T10:11:07Z DEBUG -1 2020-06-17T10:11:07Z DEBUG dnaMaxValue: 2020-06-17T10:11:07Z DEBUG 363799999 2020-06-17T10:11:07Z DEBUG dnaNextValue: 2020-06-17T10:11:07Z DEBUG 363600000 2020-06-17T10:11:07Z DEBUG dnaScope: 2020-06-17T10:11:07Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG dnaSharedCfgDN: 2020-06-17T10:11:07Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG dnaThreshold: 2020-06-17T10:11:07Z DEBUG 500 2020-06-17T10:11:07Z DEBUG dnaType: 2020-06-17T10:11:07Z DEBUG uidNumber 2020-06-17T10:11:07Z DEBUG gidNumber 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG [] 2020-06-17T10:11:07Z DEBUG Updated 0 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG New entry: cn=Read DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Read DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG ipapermission 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Read DNA Range 2020-06-17T10:11:07Z DEBUG ipapermissiontype: 2020-06-17T10:11:07Z DEBUG SYSTEM 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Read DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG ipapermission 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Read DNA Range 2020-06-17T10:11:07Z DEBUG ipapermissiontype: 2020-06-17T10:11:07Z DEBUG SYSTEM 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Posix IDs 2020-06-17T10:11:07Z DEBUG dnaExcludeScope: 2020-06-17T10:11:07Z DEBUG cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG dnaFilter: 2020-06-17T10:11:07Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2020-06-17T10:11:07Z DEBUG dnaMagicRegen: 2020-06-17T10:11:07Z DEBUG -1 2020-06-17T10:11:07Z DEBUG dnaMaxValue: 2020-06-17T10:11:07Z DEBUG 363799999 2020-06-17T10:11:07Z DEBUG dnaNextValue: 2020-06-17T10:11:07Z DEBUG 363600000 2020-06-17T10:11:07Z DEBUG dnaScope: 2020-06-17T10:11:07Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG dnaSharedCfgDN: 2020-06-17T10:11:07Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG dnaThreshold: 2020-06-17T10:11:07Z DEBUG 500 2020-06-17T10:11:07Z DEBUG dnaType: 2020-06-17T10:11:07Z DEBUG uidNumber 2020-06-17T10:11:07Z DEBUG gidNumber 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG add: '(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG add: updated value ['(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Posix IDs 2020-06-17T10:11:07Z DEBUG dnaExcludeScope: 2020-06-17T10:11:07Z DEBUG cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG dnaFilter: 2020-06-17T10:11:07Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2020-06-17T10:11:07Z DEBUG dnaMagicRegen: 2020-06-17T10:11:07Z DEBUG -1 2020-06-17T10:11:07Z DEBUG dnaMaxValue: 2020-06-17T10:11:07Z DEBUG 363799999 2020-06-17T10:11:07Z DEBUG dnaNextValue: 2020-06-17T10:11:07Z DEBUG 363600000 2020-06-17T10:11:07Z DEBUG dnaScope: 2020-06-17T10:11:07Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG dnaSharedCfgDN: 2020-06-17T10:11:07Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG dnaThreshold: 2020-06-17T10:11:07Z DEBUG 500 2020-06-17T10:11:07Z DEBUG dnaType: 2020-06-17T10:11:07Z DEBUG uidNumber 2020-06-17T10:11:07Z DEBUG gidNumber 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG extensibleObject 2020-06-17T10:11:07Z DEBUG aci: 2020-06-17T10:11:07Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:07Z DEBUG [(0, 'aci', ['(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:11:07Z DEBUG Updated 1 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-replication.update 0.050 sec 2020-06-17T10:11:07Z DEBUG Parsing update file '/usr/share/ipa/updates/40-vault.update' 2020-06-17T10:11:07Z DEBUG New entry: cn=vaults,cn=kra,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=vaults,cn=kra,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG remove: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=lin,dc=test,dc=lan")(version 3.0; acl "Allow users to create private container"; allow (add) userdn = "ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=lin,dc=test,dc=lan";)' from aci, current value [] 2020-06-17T10:11:07Z DEBUG remove: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=lin,dc=test,dc=lan")(version 3.0; acl "Allow users to create private container"; allow (add) userdn = "ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:11:07Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=lin,dc=test,dc=lan")(version 3.0; acl "Allow services to create private container"; allow (add) userdn = "ldap:///krbprincipalname=($attr.cn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan";)' from aci, current value [] 2020-06-17T10:11:07Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=lin,dc=test,dc=lan")(version 3.0; acl "Allow services to create private container"; allow (add) userdn = "ldap:///krbprincipalname=($attr.cn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#USERDN";)' from aci, current value [] 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#USERDN";)' not in aci 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#GROUPDN";)' from aci, current value [] 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#GROUPDN";)' not in aci 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' from aci, current value [] 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' not in aci 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' from aci, current value [] 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' not in aci 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#USERDN";)' from aci, current value [] 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#USERDN";)' not in aci 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#GROUPDN";)' from aci, current value [] 2020-06-17T10:11:07Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#GROUPDN";)' not in aci 2020-06-17T10:11:07Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=lin,dc=test,dc=lan")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan" and userattr="owner#SELFDN";)' from aci, current value [] 2020-06-17T10:11:07Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=lin,dc=test,dc=lan")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan" and userattr="owner#SELFDN";)' not in aci 2020-06-17T10:11:07Z DEBUG addifexist: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=lin,dc=test,dc=lan")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=lin,dc=test,dc=lan" and userattr="owner#SELFDN";)' to aci, current value [] 2020-06-17T10:11:07Z DEBUG addifexist: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=lin,dc=test,dc=lan")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=lin,dc=test,dc=lan" and userattr="owner#SELFDN";)' to aci, current value [] 2020-06-17T10:11:07Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)' to aci, current value [] 2020-06-17T10:11:07Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)' to aci, current value [] 2020-06-17T10:11:07Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)' to aci, current value [] 2020-06-17T10:11:07Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)' to aci, current value [] 2020-06-17T10:11:07Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)' to aci, current value [] 2020-06-17T10:11:07Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)' to aci, current value [] 2020-06-17T10:11:07Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";)' to aci, current value [] 2020-06-17T10:11:07Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault owners can access the vault"; allow(read, search, compare) userattr="owner#GROUPDN";)' to aci, current value [] 2020-06-17T10:11:07Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' to aci, current value [] 2020-06-17T10:11:07Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' to aci, current value [] 2020-06-17T10:11:07Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Vault owners can manage the vault"; allow(write, delete) userattr="owner#USERDN";)' to aci, current value [] 2020-06-17T10:11:07Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(write, delete) userattr="owner#GROUPDN";)' to aci, current value [] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=vaults,cn=kra,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-vault.update 0.004 sec 2020-06-17T10:11:07Z DEBUG Parsing update file '/usr/share/ipa/updates/41-caacl.update' 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=caacls,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=caacls,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG caacls 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=caacls,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG caacls 2020-06-17T10:11:07Z DEBUG [] 2020-06-17T10:11:07Z DEBUG Updated 0 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG LDAP update duration: /usr/share/ipa/updates/41-caacl.update 0.002 sec 2020-06-17T10:11:07Z DEBUG Parsing update file '/usr/share/ipa/updates/41-lightweight-cas.update' 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=cas,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=cas,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG cas 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=cas,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nsContainer 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG cas 2020-06-17T10:11:07Z DEBUG [] 2020-06-17T10:11:07Z DEBUG Updated 0 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG LDAP update duration: /usr/share/ipa/updates/41-lightweight-cas.update 0.002 sec 2020-06-17T10:11:07Z DEBUG Parsing update file '/usr/share/ipa/updates/45-roles.update' 2020-06-17T10:11:07Z DEBUG New entry: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Modify Users and Reset passwords 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Modify Users and Reset passwords 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Modify Users and Reset passwords 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Modify Users and Reset passwords 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG New entry: cn=Modify Group membership,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Modify Group membership,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Modify Group membership 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Modify Group membership 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Modify Group membership,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Modify Group membership 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Modify Group membership 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG New entry: cn=User Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=User Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG User Administrator 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Responsible for creating Users and Groups 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=User Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG User Administrator 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Responsible for creating Users and Groups 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=User Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=User Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG User Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG User Administrators 2020-06-17T10:11:07Z DEBUG add: 'cn=User Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan' to member, current value [] 2020-06-17T10:11:07Z DEBUG add: updated value ['cn=User Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=User Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG User Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG User Administrators 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG [(2, 'member', ['cn=User Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:11:07Z DEBUG Updated 1 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=Group Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Group Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Group Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Group Administrators 2020-06-17T10:11:07Z DEBUG add: 'cn=User Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan' to member, current value [] 2020-06-17T10:11:07Z DEBUG add: updated value ['cn=User Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Group Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Group Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Group Administrators 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG [(2, 'member', ['cn=User Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:11:07Z DEBUG Updated 1 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=Stage User Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Stage User Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Stage User Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Stage User Administrators 2020-06-17T10:11:07Z DEBUG add: 'cn=User Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan' to member, current value [] 2020-06-17T10:11:07Z DEBUG add: updated value ['cn=User Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Stage User Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Stage User Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Stage User Administrators 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG [(2, 'member', ['cn=User Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:11:07Z DEBUG Updated 1 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG New entry: cn=IT Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=IT Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG IT Specialist 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG IT Specialist 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=IT Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG IT Specialist 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG IT Specialist 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=Host Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Host Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Host Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Host Administrators 2020-06-17T10:11:07Z DEBUG memberOf: 2020-06-17T10:11:07Z DEBUG cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan' to member, current value [] 2020-06-17T10:11:07Z DEBUG add: updated value ['cn=IT Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Host Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Host Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Host Administrators 2020-06-17T10:11:07Z DEBUG memberOf: 2020-06-17T10:11:07Z DEBUG cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG [(2, 'member', ['cn=IT Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:11:07Z DEBUG Updated 1 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=Host Group Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Host Group Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Host Group Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Host Group Administrators 2020-06-17T10:11:07Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan' to member, current value [] 2020-06-17T10:11:07Z DEBUG add: updated value ['cn=IT Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Host Group Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Host Group Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Host Group Administrators 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG [(2, 'member', ['cn=IT Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:11:07Z DEBUG Updated 1 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=Service Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Service Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Service Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Service Administrators 2020-06-17T10:11:07Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan' to member, current value [] 2020-06-17T10:11:07Z DEBUG add: updated value ['cn=IT Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Service Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Service Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Service Administrators 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG [(2, 'member', ['cn=IT Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:11:07Z DEBUG Updated 1 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=Automount Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Automount Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Automount Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Automount Administrators 2020-06-17T10:11:07Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan' to member, current value [] 2020-06-17T10:11:07Z DEBUG add: updated value ['cn=IT Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Automount Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Automount Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Automount Administrators 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG [(2, 'member', ['cn=IT Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:11:07Z DEBUG Updated 1 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG New entry: cn=IT Security Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=IT Security Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG IT Security Specialist 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG IT Security Specialist 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=IT Security Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG IT Security Specialist 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG IT Security Specialist 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Netgroups Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Netgroups Administrators 2020-06-17T10:11:07Z DEBUG add: 'cn=IT Security Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan' to member, current value [] 2020-06-17T10:11:07Z DEBUG add: updated value ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Netgroups Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Netgroups Administrators 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG [(2, 'member', ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:11:07Z DEBUG Updated 1 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG HBAC Administrator 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG HBAC Administrator 2020-06-17T10:11:07Z DEBUG add: 'cn=IT Security Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan' to member, current value [] 2020-06-17T10:11:07Z DEBUG add: updated value ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG HBAC Administrator 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG HBAC Administrator 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG [(2, 'member', ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:11:07Z DEBUG Updated 1 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Sudo Administrator 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Sudo Administrator 2020-06-17T10:11:07Z DEBUG add: 'cn=IT Security Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan' to member, current value [] 2020-06-17T10:11:07Z DEBUG add: updated value ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Sudo Administrator 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Sudo Administrator 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG [(2, 'member', ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:11:07Z DEBUG Updated 1 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG New entry: cn=Security Architect,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Security Architect,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Security Architect 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Security Architect 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Security Architect,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Security Architect 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Security Architect 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=Delegation Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Delegation Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Delegation Administrator 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Role administration 2020-06-17T10:11:07Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan' to member, current value [] 2020-06-17T10:11:07Z DEBUG add: updated value ['cn=Security Architect,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Delegation Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Delegation Administrator 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Role administration 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG [(2, 'member', ['cn=Security Architect,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:11:07Z DEBUG Updated 1 2020-06-17T10:11:07Z DEBUG Done 2020-06-17T10:11:07Z DEBUG Updating existing entry: cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Initial value 2020-06-17T10:11:07Z DEBUG dn: cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Replication Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Replication Administrators 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG memberOf: 2020-06-17T10:11:07Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG add: 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan' to member, current value ['cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:07Z DEBUG add: updated value ['cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan', 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:07Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan' to member, current value ['cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan', 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:07Z DEBUG add: updated value ['cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan', 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan', 'cn=Security Architect,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:07Z DEBUG --------------------------------------------- 2020-06-17T10:11:07Z DEBUG Final value after applying updates 2020-06-17T10:11:07Z DEBUG dn: cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG objectClass: 2020-06-17T10:11:07Z DEBUG top 2020-06-17T10:11:07Z DEBUG groupofnames 2020-06-17T10:11:07Z DEBUG nestedgroup 2020-06-17T10:11:07Z DEBUG cn: 2020-06-17T10:11:07Z DEBUG Replication Administrators 2020-06-17T10:11:07Z DEBUG description: 2020-06-17T10:11:07Z DEBUG Replication Administrators 2020-06-17T10:11:07Z DEBUG member: 2020-06-17T10:11:07Z DEBUG cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG memberOf: 2020-06-17T10:11:07Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:07Z DEBUG [(0, 'member', ['cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan', 'cn=Security Architect,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:11:07Z DEBUG Updated 1 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG nestedgroup 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG Write IPA Configuration 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG Write IPA Configuration 2020-06-17T10:11:08Z DEBUG memberOf: 2020-06-17T10:11:08Z DEBUG cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan' to member, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['cn=Security Architect,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG nestedgroup 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG Write IPA Configuration 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG Write IPA Configuration 2020-06-17T10:11:08Z DEBUG memberOf: 2020-06-17T10:11:08Z DEBUG cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG member: 2020-06-17T10:11:08Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG [(2, 'member', ['cn=Security Architect,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:11:08Z DEBUG Updated 1 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG nestedgroup 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG Password Policy Administrator 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG Password Policy Administrator 2020-06-17T10:11:08Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan' to member, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['cn=Security Architect,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG nestedgroup 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG Password Policy Administrator 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG Password Policy Administrator 2020-06-17T10:11:08Z DEBUG member: 2020-06-17T10:11:08Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG [(2, 'member', ['cn=Security Architect,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:11:08Z DEBUG Updated 1 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG New entry: cn=Enrollment Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=Enrollment Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG nestedgroup 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG Enrollment Administrator 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG Enrollment Administrator responsible for client(host) enrollment 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=Enrollment Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG nestedgroup 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG Enrollment Administrator 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG Enrollment Administrator responsible for client(host) enrollment 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=Host Enrollment,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG nestedgroup 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG Host Enrollment 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG Host Enrollment 2020-06-17T10:11:08Z DEBUG member: 2020-06-17T10:11:08Z DEBUG cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG add: 'cn=Enrollment Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan' to member, current value ['cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: updated value ['cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan', 'cn=Enrollment Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG nestedgroup 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG Host Enrollment 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG Host Enrollment 2020-06-17T10:11:08Z DEBUG member: 2020-06-17T10:11:08Z DEBUG cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Enrollment Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG [(0, 'member', ['cn=Enrollment Administrator,cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'])] 2020-06-17T10:11:08Z DEBUG Updated 1 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/45-roles.update 0.205 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/50-7_bit_check.update' 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=7-bit check,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG 7-bit check 2020-06-17T10:11:08Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:08Z DEBUG database 2020-06-17T10:11:08Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:08Z DEBUG Enforce 7-bit clean attribute values 2020-06-17T10:11:08Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:08Z DEBUG on 2020-06-17T10:11:08Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:08Z DEBUG NS7bitAttr 2020-06-17T10:11:08Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:08Z DEBUG NS7bitAttr_Init 2020-06-17T10:11:08Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:08Z DEBUG libattr-unique-plugin 2020-06-17T10:11:08Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:08Z DEBUG betxnpreoperation 2020-06-17T10:11:08Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:08Z DEBUG 389 Project 2020-06-17T10:11:08Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:08Z DEBUG 1.4.2.4 2020-06-17T10:11:08Z DEBUG nsslapd-pluginarg0: 2020-06-17T10:11:08Z DEBUG uid 2020-06-17T10:11:08Z DEBUG nsslapd-pluginarg1: 2020-06-17T10:11:08Z DEBUG mail 2020-06-17T10:11:08Z DEBUG nsslapd-pluginarg2: 2020-06-17T10:11:08Z DEBUG , 2020-06-17T10:11:08Z DEBUG nsslapd-pluginarg3: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsSlapdPlugin 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG replace: userpassword not found, skipping 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG 7-bit check 2020-06-17T10:11:08Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:08Z DEBUG database 2020-06-17T10:11:08Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:08Z DEBUG Enforce 7-bit clean attribute values 2020-06-17T10:11:08Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:08Z DEBUG on 2020-06-17T10:11:08Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:08Z DEBUG NS7bitAttr 2020-06-17T10:11:08Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:08Z DEBUG NS7bitAttr_Init 2020-06-17T10:11:08Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:08Z DEBUG libattr-unique-plugin 2020-06-17T10:11:08Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:08Z DEBUG betxnpreoperation 2020-06-17T10:11:08Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:08Z DEBUG 389 Project 2020-06-17T10:11:08Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:08Z DEBUG 1.4.2.4 2020-06-17T10:11:08Z DEBUG nsslapd-pluginarg0: 2020-06-17T10:11:08Z DEBUG uid 2020-06-17T10:11:08Z DEBUG nsslapd-pluginarg1: 2020-06-17T10:11:08Z DEBUG mail 2020-06-17T10:11:08Z DEBUG nsslapd-pluginarg2: 2020-06-17T10:11:08Z DEBUG , 2020-06-17T10:11:08Z DEBUG nsslapd-pluginarg3: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsSlapdPlugin 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG [] 2020-06-17T10:11:08Z DEBUG Updated 0 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-7_bit_check.update 0.006 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/50-dogtag10-migration.update' 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=aclResources,o=ipaca 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=aclResources,o=ipaca 2020-06-17T10:11:08Z DEBUG resourceACLS: 2020-06-17T10:11:08Z DEBUG certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete 2020-06-17T10:11:08Z DEBUG certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml 2020-06-17T10:11:08Z DEBUG certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter 2020-06-17T10:11:08Z DEBUG certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log 2020-06-17T10:11:08Z DEBUG certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2020-06-17T10:11:08Z DEBUG certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2020-06-17T10:11:08Z DEBUG certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets 2020-06-17T10:11:08Z DEBUG certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory 2020-06-17T10:11:08Z DEBUG certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate 2020-06-17T10:11:08Z DEBUG certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates 2020-06-17T10:11:08Z DEBUG certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests 2020-06-17T10:11:08Z DEBUG certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request 2020-06-17T10:11:08Z DEBUG certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information 2020-06-17T10:11:08Z DEBUG certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests 2020-06-17T10:11:08Z DEBUG certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl 2020-06-17T10:11:08Z DEBUG certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate 2020-06-17T10:11:08Z DEBUG certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates 2020-06-17T10:11:08Z DEBUG certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain 2020-06-17T10:11:08Z DEBUG certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL 2020-06-17T10:11:08Z DEBUG certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request 2020-06-17T10:11:08Z DEBUG certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status 2020-06-17T10:11:08Z DEBUG certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request 2020-06-17T10:11:08Z DEBUG certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate 2020-06-17T10:11:08Z DEBUG certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request 2020-06-17T10:11:08Z DEBUG certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile 2020-06-17T10:11:08Z DEBUG certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles 2020-06-17T10:11:08Z DEBUG certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile 2020-06-17T10:11:08Z DEBUG certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles 2020-06-17T10:11:08Z DEBUG certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles 2020-06-17T10:11:08Z DEBUG certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests 2020-06-17T10:11:08Z DEBUG certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA 2020-06-17T10:11:08Z DEBUG certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics 2020-06-17T10:11:08Z DEBUG certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups 2020-06-17T10:11:08Z DEBUG certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information 2020-06-17T10:11:08Z DEBUG certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent 2020-06-17T10:11:08Z DEBUG certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration. 2020-06-17T10:11:08Z DEBUG certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration. 2020-06-17T10:11:08Z DEBUG certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout 2020-06-17T10:11:08Z DEBUG certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations 2020-06-17T10:11:08Z DEBUG certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations 2020-06-17T10:11:08Z DEBUG certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations 2020-06-17T10:11:08Z DEBUG certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests. 2020-06-17T10:11:08Z DEBUG certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations 2020-06-17T10:11:08Z DEBUG certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities 2020-06-17T10:11:08Z DEBUG certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities 2020-06-17T10:11:08Z DEBUG certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities 2020-06-17T10:11:08Z DEBUG certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles 2020-06-17T10:11:08Z DEBUG certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG CertACLS 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG aclResources 2020-06-17T10:11:08Z DEBUG addifexist: 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities'] 2020-06-17T10:11:08Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout'] 2020-06-17T10:11:08Z DEBUG addifexist: 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout'] 2020-06-17T10:11:08Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations'] 2020-06-17T10:11:08Z DEBUG addifexist: 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations'] 2020-06-17T10:11:08Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations'] 2020-06-17T10:11:08Z DEBUG addifexist: 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations'] 2020-06-17T10:11:08Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations'] 2020-06-17T10:11:08Z DEBUG addifexist: 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations'] 2020-06-17T10:11:08Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations'] 2020-06-17T10:11:08Z DEBUG replace: certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group":Anybody is allowed to read domain.xml but only Subsystem group is allowed to modify the domain.xml not found, skipping 2020-06-17T10:11:08Z DEBUG replace: certServer.ca.connectorInfo:read,modify:allow (modify,read) group="Enterprise KRA Administrators":Only Enterprise Administrators are allowed to update the connector information not found, skipping 2020-06-17T10:11:08Z DEBUG addifexist: 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations'] 2020-06-17T10:11:08Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=aclResources,o=ipaca 2020-06-17T10:11:08Z DEBUG resourceACLS: 2020-06-17T10:11:08Z DEBUG certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete 2020-06-17T10:11:08Z DEBUG certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml 2020-06-17T10:11:08Z DEBUG certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter 2020-06-17T10:11:08Z DEBUG certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log 2020-06-17T10:11:08Z DEBUG certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2020-06-17T10:11:08Z DEBUG certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2020-06-17T10:11:08Z DEBUG certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets 2020-06-17T10:11:08Z DEBUG certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify 2020-06-17T10:11:08Z DEBUG certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory 2020-06-17T10:11:08Z DEBUG certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate 2020-06-17T10:11:08Z DEBUG certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates 2020-06-17T10:11:08Z DEBUG certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests 2020-06-17T10:11:08Z DEBUG certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request 2020-06-17T10:11:08Z DEBUG certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information 2020-06-17T10:11:08Z DEBUG certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests 2020-06-17T10:11:08Z DEBUG certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl 2020-06-17T10:11:08Z DEBUG certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate 2020-06-17T10:11:08Z DEBUG certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates 2020-06-17T10:11:08Z DEBUG certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain 2020-06-17T10:11:08Z DEBUG certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL 2020-06-17T10:11:08Z DEBUG certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request 2020-06-17T10:11:08Z DEBUG certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status 2020-06-17T10:11:08Z DEBUG certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request 2020-06-17T10:11:08Z DEBUG certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate 2020-06-17T10:11:08Z DEBUG certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request 2020-06-17T10:11:08Z DEBUG certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile 2020-06-17T10:11:08Z DEBUG certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles 2020-06-17T10:11:08Z DEBUG certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile 2020-06-17T10:11:08Z DEBUG certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles 2020-06-17T10:11:08Z DEBUG certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles 2020-06-17T10:11:08Z DEBUG certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests 2020-06-17T10:11:08Z DEBUG certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA 2020-06-17T10:11:08Z DEBUG certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics 2020-06-17T10:11:08Z DEBUG certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups 2020-06-17T10:11:08Z DEBUG certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information 2020-06-17T10:11:08Z DEBUG certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent 2020-06-17T10:11:08Z DEBUG certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration. 2020-06-17T10:11:08Z DEBUG certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration. 2020-06-17T10:11:08Z DEBUG certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout 2020-06-17T10:11:08Z DEBUG certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations 2020-06-17T10:11:08Z DEBUG certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations 2020-06-17T10:11:08Z DEBUG certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations 2020-06-17T10:11:08Z DEBUG certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests. 2020-06-17T10:11:08Z DEBUG certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations 2020-06-17T10:11:08Z DEBUG certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities 2020-06-17T10:11:08Z DEBUG certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities 2020-06-17T10:11:08Z DEBUG certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities 2020-06-17T10:11:08Z DEBUG certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles 2020-06-17T10:11:08Z DEBUG certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities 2020-06-17T10:11:08Z DEBUG certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout 2020-06-17T10:11:08Z DEBUG certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations 2020-06-17T10:11:08Z DEBUG certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations 2020-06-17T10:11:08Z DEBUG certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations 2020-06-17T10:11:08Z DEBUG certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations 2020-06-17T10:11:08Z DEBUG certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG CertACLS 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG aclResources 2020-06-17T10:11:08Z DEBUG [] 2020-06-17T10:11:08Z DEBUG Updated 0 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-dogtag10-migration.update 0.014 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/50-groupuuid.update' 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG posixgroup 2020-06-17T10:11:08Z DEBUG ipausergroup 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG nestedGroup 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG admins 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG Account administrators group 2020-06-17T10:11:08Z DEBUG gidNumber: 2020-06-17T10:11:08Z DEBUG 363600000 2020-06-17T10:11:08Z DEBUG member: 2020-06-17T10:11:08Z DEBUG uid=admin,cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG ipaUniqueID: 2020-06-17T10:11:08Z DEBUG 3031c3ac-b082-11ea-8acc-525400885899 2020-06-17T10:11:08Z DEBUG memberOf: 2020-06-17T10:11:08Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Host Enrollment,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG add: 'ipaobject' to objectclass, current value ['top', 'groupofnames', 'posixgroup', 'ipausergroup', 'ipaobject', 'nestedGroup'] 2020-06-17T10:11:08Z DEBUG add: updated value ['top', 'groupofnames', 'posixgroup', 'ipausergroup', 'nestedGroup', 'ipaobject'] 2020-06-17T10:11:08Z DEBUG addifnew: 'autogenerate' to ipaUniqueID, current value ['3031c3ac-b082-11ea-8acc-525400885899'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG posixgroup 2020-06-17T10:11:08Z DEBUG ipausergroup 2020-06-17T10:11:08Z DEBUG nestedGroup 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG admins 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG Account administrators group 2020-06-17T10:11:08Z DEBUG gidNumber: 2020-06-17T10:11:08Z DEBUG 363600000 2020-06-17T10:11:08Z DEBUG member: 2020-06-17T10:11:08Z DEBUG uid=admin,cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG ipaUniqueID: 2020-06-17T10:11:08Z DEBUG 3031c3ac-b082-11ea-8acc-525400885899 2020-06-17T10:11:08Z DEBUG memberOf: 2020-06-17T10:11:08Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Host Enrollment,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG [] 2020-06-17T10:11:08Z DEBUG Updated 0 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=ipausers,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=ipausers,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG nestedgroup 2020-06-17T10:11:08Z DEBUG ipausergroup 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG Default group for all users 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG ipausers 2020-06-17T10:11:08Z DEBUG ipaUniqueID: 2020-06-17T10:11:08Z DEBUG 3038a0d2-b082-11ea-821d-525400885899 2020-06-17T10:11:08Z DEBUG add: 'ipaobject' to objectclass, current value ['top', 'groupofnames', 'nestedgroup', 'ipausergroup', 'ipaobject'] 2020-06-17T10:11:08Z DEBUG add: updated value ['top', 'groupofnames', 'nestedgroup', 'ipausergroup', 'ipaobject'] 2020-06-17T10:11:08Z DEBUG addifnew: 'autogenerate' to ipaUniqueID, current value ['3038a0d2-b082-11ea-821d-525400885899'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=ipausers,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG nestedgroup 2020-06-17T10:11:08Z DEBUG ipausergroup 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG Default group for all users 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG ipausers 2020-06-17T10:11:08Z DEBUG ipaUniqueID: 2020-06-17T10:11:08Z DEBUG 3038a0d2-b082-11ea-821d-525400885899 2020-06-17T10:11:08Z DEBUG [] 2020-06-17T10:11:08Z DEBUG Updated 0 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=editors,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=editors,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG posixgroup 2020-06-17T10:11:08Z DEBUG ipausergroup 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG nestedGroup 2020-06-17T10:11:08Z DEBUG gidNumber: 2020-06-17T10:11:08Z DEBUG 363600002 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG Limited admins who can edit other users 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG editors 2020-06-17T10:11:08Z DEBUG ipaUniqueID: 2020-06-17T10:11:08Z DEBUG 3039190e-b082-11ea-a33d-525400885899 2020-06-17T10:11:08Z DEBUG add: 'ipaobject' to objectclass, current value ['top', 'groupofnames', 'posixgroup', 'ipausergroup', 'ipaobject', 'nestedGroup'] 2020-06-17T10:11:08Z DEBUG add: updated value ['top', 'groupofnames', 'posixgroup', 'ipausergroup', 'nestedGroup', 'ipaobject'] 2020-06-17T10:11:08Z DEBUG addifnew: 'autogenerate' to ipaUniqueID, current value ['3039190e-b082-11ea-a33d-525400885899'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=editors,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG posixgroup 2020-06-17T10:11:08Z DEBUG ipausergroup 2020-06-17T10:11:08Z DEBUG nestedGroup 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG gidNumber: 2020-06-17T10:11:08Z DEBUG 363600002 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG Limited admins who can edit other users 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG editors 2020-06-17T10:11:08Z DEBUG ipaUniqueID: 2020-06-17T10:11:08Z DEBUG 3039190e-b082-11ea-a33d-525400885899 2020-06-17T10:11:08Z DEBUG [] 2020-06-17T10:11:08Z DEBUG Updated 0 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-groupuuid.update 0.013 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/50-hbacservice.update' 2020-06-17T10:11:08Z DEBUG New entry: cn=crond,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=crond,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectclass: 2020-06-17T10:11:08Z DEBUG ipahbacservice 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG crond 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG crond 2020-06-17T10:11:08Z DEBUG ipauniqueid: 2020-06-17T10:11:08Z DEBUG autogenerate 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=crond,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectclass: 2020-06-17T10:11:08Z DEBUG ipahbacservice 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG crond 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG crond 2020-06-17T10:11:08Z DEBUG ipauniqueid: 2020-06-17T10:11:08Z DEBUG autogenerate 2020-06-17T10:11:08Z DEBUG New entry: cn=vsftpd,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=vsftpd,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectclass: 2020-06-17T10:11:08Z DEBUG ipahbacservice 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG vsftpd 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG vsftpd 2020-06-17T10:11:08Z DEBUG ipauniqueid: 2020-06-17T10:11:08Z DEBUG autogenerate 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=vsftpd,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectclass: 2020-06-17T10:11:08Z DEBUG ipahbacservice 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG vsftpd 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG vsftpd 2020-06-17T10:11:08Z DEBUG ipauniqueid: 2020-06-17T10:11:08Z DEBUG autogenerate 2020-06-17T10:11:08Z DEBUG New entry: cn=proftpd,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=proftpd,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectclass: 2020-06-17T10:11:08Z DEBUG ipahbacservice 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG proftpd 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG proftpd 2020-06-17T10:11:08Z DEBUG ipauniqueid: 2020-06-17T10:11:08Z DEBUG autogenerate 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=proftpd,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectclass: 2020-06-17T10:11:08Z DEBUG ipahbacservice 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG proftpd 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG proftpd 2020-06-17T10:11:08Z DEBUG ipauniqueid: 2020-06-17T10:11:08Z DEBUG autogenerate 2020-06-17T10:11:08Z DEBUG New entry: cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectclass: 2020-06-17T10:11:08Z DEBUG ipahbacservice 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG pure-ftpd 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG pure-ftpd 2020-06-17T10:11:08Z DEBUG ipauniqueid: 2020-06-17T10:11:08Z DEBUG autogenerate 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectclass: 2020-06-17T10:11:08Z DEBUG ipahbacservice 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG pure-ftpd 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG pure-ftpd 2020-06-17T10:11:08Z DEBUG ipauniqueid: 2020-06-17T10:11:08Z DEBUG autogenerate 2020-06-17T10:11:08Z DEBUG New entry: cn=gssftp,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=gssftp,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectclass: 2020-06-17T10:11:08Z DEBUG ipahbacservice 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG gssftp 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG gssftp 2020-06-17T10:11:08Z DEBUG ipauniqueid: 2020-06-17T10:11:08Z DEBUG autogenerate 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=gssftp,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectclass: 2020-06-17T10:11:08Z DEBUG ipahbacservice 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG gssftp 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG gssftp 2020-06-17T10:11:08Z DEBUG ipauniqueid: 2020-06-17T10:11:08Z DEBUG autogenerate 2020-06-17T10:11:08Z DEBUG New entry: cn=ftp,cn=hbacservicegroups,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=ftp,cn=hbacservicegroups,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG ipahbacservicegroup 2020-06-17T10:11:08Z DEBUG nestedGroup 2020-06-17T10:11:08Z DEBUG groupOfNames 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG ftp 2020-06-17T10:11:08Z DEBUG ipauniqueid: 2020-06-17T10:11:08Z DEBUG autogenerate 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG Default group of ftp related services 2020-06-17T10:11:08Z DEBUG member: 2020-06-17T10:11:08Z DEBUG cn=ftp,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=proftpd,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=vsftpd,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=gssftp,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=ftp,cn=hbacservicegroups,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG ipahbacservicegroup 2020-06-17T10:11:08Z DEBUG nestedGroup 2020-06-17T10:11:08Z DEBUG groupOfNames 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG ftp 2020-06-17T10:11:08Z DEBUG ipauniqueid: 2020-06-17T10:11:08Z DEBUG autogenerate 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG Default group of ftp related services 2020-06-17T10:11:08Z DEBUG member: 2020-06-17T10:11:08Z DEBUG cn=ftp,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=proftpd,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=vsftpd,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=gssftp,cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-hbacservice.update 0.056 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/50-ipaconfig.update' 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=ipaConfig,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=ipaConfig,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG ipaGuiConfig 2020-06-17T10:11:08Z DEBUG ipaConfigObject 2020-06-17T10:11:08Z DEBUG ipaUserSearchFields: 2020-06-17T10:11:08Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2020-06-17T10:11:08Z DEBUG ipaGroupSearchFields: 2020-06-17T10:11:08Z DEBUG cn,description 2020-06-17T10:11:08Z DEBUG ipaSearchTimeLimit: 2020-06-17T10:11:08Z DEBUG 2 2020-06-17T10:11:08Z DEBUG ipaSearchRecordsLimit: 2020-06-17T10:11:08Z DEBUG 100 2020-06-17T10:11:08Z DEBUG ipaHomesRootDir: 2020-06-17T10:11:08Z DEBUG /home 2020-06-17T10:11:08Z DEBUG ipaDefaultLoginShell: 2020-06-17T10:11:08Z DEBUG /bin/sh 2020-06-17T10:11:08Z DEBUG ipaDefaultPrimaryGroup: 2020-06-17T10:11:08Z DEBUG ipausers 2020-06-17T10:11:08Z DEBUG ipaMaxUsernameLength: 2020-06-17T10:11:08Z DEBUG 32 2020-06-17T10:11:08Z DEBUG ipaMaxHostnameLength: 2020-06-17T10:11:08Z DEBUG 64 2020-06-17T10:11:08Z DEBUG ipaPwdExpAdvNotify: 2020-06-17T10:11:08Z DEBUG 4 2020-06-17T10:11:08Z DEBUG ipaGroupObjectClasses: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG nestedgroup 2020-06-17T10:11:08Z DEBUG ipausergroup 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG ipaUserObjectClasses: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG person 2020-06-17T10:11:08Z DEBUG organizationalperson 2020-06-17T10:11:08Z DEBUG inetorgperson 2020-06-17T10:11:08Z DEBUG inetuser 2020-06-17T10:11:08Z DEBUG posixaccount 2020-06-17T10:11:08Z DEBUG krbprincipalaux 2020-06-17T10:11:08Z DEBUG krbticketpolicyaux 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG ipasshuser 2020-06-17T10:11:08Z DEBUG ipaDefaultEmailDomain: 2020-06-17T10:11:08Z DEBUG lin.test.lan 2020-06-17T10:11:08Z DEBUG ipaMigrationEnabled: 2020-06-17T10:11:08Z DEBUG FALSE 2020-06-17T10:11:08Z DEBUG ipaConfigString: 2020-06-17T10:11:08Z DEBUG AllowNThash 2020-06-17T10:11:08Z DEBUG KDC:Disable Last Success 2020-06-17T10:11:08Z DEBUG ipaSELinuxUserMapOrder: 2020-06-17T10:11:08Z DEBUG guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$sysadm_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 2020-06-17T10:11:08Z DEBUG ipaSELinuxUserMapDefault: 2020-06-17T10:11:08Z DEBUG unconfined_u:s0-s0:c0.c1023 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG ipaConfig 2020-06-17T10:11:08Z DEBUG ipaCertificateSubjectBase: 2020-06-17T10:11:08Z DEBUG O=LIN.TEST.LAN 2020-06-17T10:11:08Z DEBUG replace: guest_u:s0$$xguest_u:s0$$user_u:s0$$staff_u:s0-s0:c0.c1023$$sysadm_u:s0-s0:c0.c1023$$unconfined_u:s0-s0:c0.c1023 not found, skipping 2020-06-17T10:11:08Z DEBUG replace: ipaSELinuxUserMapOrder: guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 not found, skipping 2020-06-17T10:11:08Z DEBUG replace: guest_u:s0$xguest_u:s0$user_u:s0-s0:c0.c1023$staff_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 not found, skipping 2020-06-17T10:11:08Z DEBUG add: 'unconfined_u:s0-s0:c0.c1023' to ipaSELinuxUserMapDefault, current value ['unconfined_u:s0-s0:c0.c1023'] 2020-06-17T10:11:08Z DEBUG add: updated value ['unconfined_u:s0-s0:c0.c1023'] 2020-06-17T10:11:08Z DEBUG add: 'ipasshuser' to ipaUserObjectClasses, current value ['top', 'person', 'organizationalperson', 'inetorgperson', 'inetuser', 'posixaccount', 'krbprincipalaux', 'krbticketpolicyaux', 'ipaobject', 'ipasshuser'] 2020-06-17T10:11:08Z DEBUG add: updated value ['top', 'person', 'organizationalperson', 'inetorgperson', 'inetuser', 'posixaccount', 'krbprincipalaux', 'krbticketpolicyaux', 'ipaobject', 'ipasshuser'] 2020-06-17T10:11:08Z DEBUG remove: 'AllowLMhash' from ipaConfigString, current value ['AllowNThash', 'KDC:Disable Last Success'] 2020-06-17T10:11:08Z DEBUG remove: 'AllowLMhash' not in ipaConfigString 2020-06-17T10:11:08Z DEBUG add: 'ipaUserAuthTypeClass' to objectClass, current value ['nsContainer', 'top', 'ipaGuiConfig', 'ipaConfigObject'] 2020-06-17T10:11:08Z DEBUG add: updated value ['nsContainer', 'top', 'ipaGuiConfig', 'ipaConfigObject', 'ipaUserAuthTypeClass'] 2020-06-17T10:11:08Z DEBUG add: 'ipaNameResolutionData' to objectClass, current value ['nsContainer', 'top', 'ipaGuiConfig', 'ipaConfigObject', 'ipaUserAuthTypeClass'] 2020-06-17T10:11:08Z DEBUG add: updated value ['nsContainer', 'top', 'ipaGuiConfig', 'ipaConfigObject', 'ipaUserAuthTypeClass', 'ipaNameResolutionData'] 2020-06-17T10:11:08Z DEBUG addifnew: '64' to ipamaxhostnamelength, current value ['64'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=ipaConfig,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG ipaGuiConfig 2020-06-17T10:11:08Z DEBUG ipaConfigObject 2020-06-17T10:11:08Z DEBUG ipaUserAuthTypeClass 2020-06-17T10:11:08Z DEBUG ipaNameResolutionData 2020-06-17T10:11:08Z DEBUG ipaUserSearchFields: 2020-06-17T10:11:08Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2020-06-17T10:11:08Z DEBUG ipaGroupSearchFields: 2020-06-17T10:11:08Z DEBUG cn,description 2020-06-17T10:11:08Z DEBUG ipaSearchTimeLimit: 2020-06-17T10:11:08Z DEBUG 2 2020-06-17T10:11:08Z DEBUG ipaSearchRecordsLimit: 2020-06-17T10:11:08Z DEBUG 100 2020-06-17T10:11:08Z DEBUG ipaHomesRootDir: 2020-06-17T10:11:08Z DEBUG /home 2020-06-17T10:11:08Z DEBUG ipaDefaultLoginShell: 2020-06-17T10:11:08Z DEBUG /bin/sh 2020-06-17T10:11:08Z DEBUG ipaDefaultPrimaryGroup: 2020-06-17T10:11:08Z DEBUG ipausers 2020-06-17T10:11:08Z DEBUG ipaMaxUsernameLength: 2020-06-17T10:11:08Z DEBUG 32 2020-06-17T10:11:08Z DEBUG ipaMaxHostnameLength: 2020-06-17T10:11:08Z DEBUG 64 2020-06-17T10:11:08Z DEBUG ipaPwdExpAdvNotify: 2020-06-17T10:11:08Z DEBUG 4 2020-06-17T10:11:08Z DEBUG ipaGroupObjectClasses: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG nestedgroup 2020-06-17T10:11:08Z DEBUG ipausergroup 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG ipaUserObjectClasses: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG person 2020-06-17T10:11:08Z DEBUG organizationalperson 2020-06-17T10:11:08Z DEBUG inetorgperson 2020-06-17T10:11:08Z DEBUG inetuser 2020-06-17T10:11:08Z DEBUG posixaccount 2020-06-17T10:11:08Z DEBUG krbprincipalaux 2020-06-17T10:11:08Z DEBUG krbticketpolicyaux 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG ipasshuser 2020-06-17T10:11:08Z DEBUG ipaDefaultEmailDomain: 2020-06-17T10:11:08Z DEBUG lin.test.lan 2020-06-17T10:11:08Z DEBUG ipaMigrationEnabled: 2020-06-17T10:11:08Z DEBUG FALSE 2020-06-17T10:11:08Z DEBUG ipaConfigString: 2020-06-17T10:11:08Z DEBUG AllowNThash 2020-06-17T10:11:08Z DEBUG KDC:Disable Last Success 2020-06-17T10:11:08Z DEBUG ipaSELinuxUserMapOrder: 2020-06-17T10:11:08Z DEBUG guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$sysadm_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 2020-06-17T10:11:08Z DEBUG ipaSELinuxUserMapDefault: 2020-06-17T10:11:08Z DEBUG unconfined_u:s0-s0:c0.c1023 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG ipaConfig 2020-06-17T10:11:08Z DEBUG ipaCertificateSubjectBase: 2020-06-17T10:11:08Z DEBUG O=LIN.TEST.LAN 2020-06-17T10:11:08Z DEBUG [(0, 'objectClass', ['ipaUserAuthTypeClass', 'ipaNameResolutionData'])] 2020-06-17T10:11:08Z DEBUG Updated 1 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-ipaconfig.update 0.014 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/50-krbenctypes.update' 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG LIN.TEST.LAN 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG krbrealmcontainer 2020-06-17T10:11:08Z DEBUG krbticketpolicyaux 2020-06-17T10:11:08Z DEBUG krbSubTrees: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG krbSearchScope: 2020-06-17T10:11:08Z DEBUG 2 2020-06-17T10:11:08Z DEBUG krbSupportedEncSaltTypes: 2020-06-17T10:11:08Z DEBUG aes256-cts:normal 2020-06-17T10:11:08Z DEBUG aes256-cts:special 2020-06-17T10:11:08Z DEBUG aes128-cts:normal 2020-06-17T10:11:08Z DEBUG aes128-cts:special 2020-06-17T10:11:08Z DEBUG aes128-sha2:normal 2020-06-17T10:11:08Z DEBUG aes128-sha2:special 2020-06-17T10:11:08Z DEBUG aes256-sha2:normal 2020-06-17T10:11:08Z DEBUG aes256-sha2:special 2020-06-17T10:11:08Z DEBUG camellia128-cts-cmac:normal 2020-06-17T10:11:08Z DEBUG camellia128-cts-cmac:special 2020-06-17T10:11:08Z DEBUG camellia256-cts-cmac:normal 2020-06-17T10:11:08Z DEBUG camellia256-cts-cmac:special 2020-06-17T10:11:08Z DEBUG krbMaxTicketLife: 2020-06-17T10:11:08Z DEBUG 86400 2020-06-17T10:11:08Z DEBUG krbMaxRenewableAge: 2020-06-17T10:11:08Z DEBUG 604800 2020-06-17T10:11:08Z DEBUG krbDefaultEncSaltTypes: 2020-06-17T10:11:08Z DEBUG aes256-cts:special 2020-06-17T10:11:08Z DEBUG aes128-cts:special 2020-06-17T10:11:08Z DEBUG krbMKey: 2020-06-17T10:11:08Z DEBUG XXXXXXXX 2020-06-17T10:11:08Z DEBUG krbPwdPolicyReference: 2020-06-17T10:11:08Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG add: 'camellia128-cts-cmac:normal' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special'] 2020-06-17T10:11:08Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal'] 2020-06-17T10:11:08Z DEBUG add: 'camellia128-cts-cmac:special' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal'] 2020-06-17T10:11:08Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special'] 2020-06-17T10:11:08Z DEBUG add: 'camellia256-cts-cmac:normal' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special'] 2020-06-17T10:11:08Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal'] 2020-06-17T10:11:08Z DEBUG add: 'camellia256-cts-cmac:special' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal'] 2020-06-17T10:11:08Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special'] 2020-06-17T10:11:08Z DEBUG add: 'aes128-sha2:normal' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special'] 2020-06-17T10:11:08Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal'] 2020-06-17T10:11:08Z DEBUG add: 'aes128-sha2:special' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal'] 2020-06-17T10:11:08Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal', 'aes128-sha2:special'] 2020-06-17T10:11:08Z DEBUG add: 'aes256-sha2:normal' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal', 'aes128-sha2:special'] 2020-06-17T10:11:08Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal'] 2020-06-17T10:11:08Z DEBUG add: 'aes256-sha2:special' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal'] 2020-06-17T10:11:08Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG LIN.TEST.LAN 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG krbrealmcontainer 2020-06-17T10:11:08Z DEBUG krbticketpolicyaux 2020-06-17T10:11:08Z DEBUG krbSubTrees: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG krbSearchScope: 2020-06-17T10:11:08Z DEBUG 2 2020-06-17T10:11:08Z DEBUG krbSupportedEncSaltTypes: 2020-06-17T10:11:08Z DEBUG aes256-cts:normal 2020-06-17T10:11:08Z DEBUG aes256-cts:special 2020-06-17T10:11:08Z DEBUG aes128-cts:normal 2020-06-17T10:11:08Z DEBUG aes128-cts:special 2020-06-17T10:11:08Z DEBUG camellia128-cts-cmac:normal 2020-06-17T10:11:08Z DEBUG camellia128-cts-cmac:special 2020-06-17T10:11:08Z DEBUG camellia256-cts-cmac:normal 2020-06-17T10:11:08Z DEBUG camellia256-cts-cmac:special 2020-06-17T10:11:08Z DEBUG aes128-sha2:normal 2020-06-17T10:11:08Z DEBUG aes128-sha2:special 2020-06-17T10:11:08Z DEBUG aes256-sha2:normal 2020-06-17T10:11:08Z DEBUG aes256-sha2:special 2020-06-17T10:11:08Z DEBUG krbMaxTicketLife: 2020-06-17T10:11:08Z DEBUG 86400 2020-06-17T10:11:08Z DEBUG krbMaxRenewableAge: 2020-06-17T10:11:08Z DEBUG 604800 2020-06-17T10:11:08Z DEBUG krbDefaultEncSaltTypes: 2020-06-17T10:11:08Z DEBUG aes256-cts:special 2020-06-17T10:11:08Z DEBUG aes128-cts:special 2020-06-17T10:11:08Z DEBUG krbMKey: 2020-06-17T10:11:08Z DEBUG XXXXXXXX 2020-06-17T10:11:08Z DEBUG krbPwdPolicyReference: 2020-06-17T10:11:08Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG [] 2020-06-17T10:11:08Z DEBUG Updated 0 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-krbenctypes.update 0.007 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/50-nis.update' 2020-06-17T10:11:08Z DEBUG Executing upgrade plugin: update_nis_configuration 2020-06-17T10:11:08Z DEBUG raw: update_nis_configuration 2020-06-17T10:11:08Z DEBUG Skipping NIS update, NIS Server is not configured 2020-06-17T10:11:08Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:11:08Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-nis.update 0.002 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/55-pbacmemberof.update' 2020-06-17T10:11:08Z DEBUG New entry: cn=Update PBAC memberOf 138116814,cn=memberof task,cn=tasks,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=Update PBAC memberOf 138116814,cn=memberof task,cn=tasks,cn=config 2020-06-17T10:11:08Z DEBUG add: 'top' to objectClass, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['top'] 2020-06-17T10:11:08Z DEBUG add: 'extensibleObject' to objectClass, current value ['top'] 2020-06-17T10:11:08Z DEBUG add: updated value ['top', 'extensibleObject'] 2020-06-17T10:11:08Z DEBUG add: 'IPA PBAC memberOf 138116814' to cn, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['IPA PBAC memberOf 138116814'] 2020-06-17T10:11:08Z DEBUG add: 'cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan' to basedn, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: '(objectclass=*)' to filter, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['(objectclass=*)'] 2020-06-17T10:11:08Z DEBUG add: '10' to ttl, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['10'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=Update PBAC memberOf 138116814,cn=memberof task,cn=tasks,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG IPA PBAC memberOf 138116814 2020-06-17T10:11:08Z DEBUG basedn: 2020-06-17T10:11:08Z DEBUG cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG filter: 2020-06-17T10:11:08Z DEBUG (objectclass=*) 2020-06-17T10:11:08Z DEBUG ttl: 2020-06-17T10:11:08Z DEBUG 10 2020-06-17T10:11:08Z DEBUG New entry: cn=Update Role memberOf 138116814,cn=memberof task,cn=tasks,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=Update Role memberOf 138116814,cn=memberof task,cn=tasks,cn=config 2020-06-17T10:11:08Z DEBUG add: 'top' to objectClass, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['top'] 2020-06-17T10:11:08Z DEBUG add: 'extensibleObject' to objectClass, current value ['top'] 2020-06-17T10:11:08Z DEBUG add: updated value ['top', 'extensibleObject'] 2020-06-17T10:11:08Z DEBUG add: 'Update Role memberOf 138116814' to cn, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['Update Role memberOf 138116814'] 2020-06-17T10:11:08Z DEBUG add: 'cn=roles,cn=accounts,dc=lin,dc=test,dc=lan' to basedn, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['cn=roles,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: '(objectclass=*)' to filter, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['(objectclass=*)'] 2020-06-17T10:11:08Z DEBUG add: '10' to ttl, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['10'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=Update Role memberOf 138116814,cn=memberof task,cn=tasks,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG Update Role memberOf 138116814 2020-06-17T10:11:08Z DEBUG basedn: 2020-06-17T10:11:08Z DEBUG cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG filter: 2020-06-17T10:11:08Z DEBUG (objectclass=*) 2020-06-17T10:11:08Z DEBUG ttl: 2020-06-17T10:11:08Z DEBUG 10 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/55-pbacmemberof.update 0.018 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/59-trusts-sysacount.update' 2020-06-17T10:11:08Z DEBUG New entry: cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG GroupOfNames 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG adtrust agents 2020-06-17T10:11:08Z DEBUG add: 'nestedgroup' to objectClass, current value ['GroupOfNames', 'top'] 2020-06-17T10:11:08Z DEBUG add: updated value ['GroupOfNames', 'top', 'nestedgroup'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG GroupOfNames 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nestedgroup 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG adtrust agents 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/59-trusts-sysacount.update 0.006 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/60-trusts.update' 2020-06-17T10:11:08Z DEBUG New entry: cn=trust admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=trust admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG ipausergroup 2020-06-17T10:11:08Z DEBUG nestedgroup 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG trust admins 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG Trusts administrators group 2020-06-17T10:11:08Z DEBUG member: 2020-06-17T10:11:08Z DEBUG uid=admin,cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG nsAccountLock: 2020-06-17T10:11:08Z DEBUG FALSE 2020-06-17T10:11:08Z DEBUG ipaUniqueID: 2020-06-17T10:11:08Z DEBUG autogenerate 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=trust admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG ipausergroup 2020-06-17T10:11:08Z DEBUG nestedgroup 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG trust admins 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG Trusts administrators group 2020-06-17T10:11:08Z DEBUG member: 2020-06-17T10:11:08Z DEBUG uid=admin,cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG nsAccountLock: 2020-06-17T10:11:08Z DEBUG FALSE 2020-06-17T10:11:08Z DEBUG ipaUniqueID: 2020-06-17T10:11:08Z DEBUG autogenerate 2020-06-17T10:11:08Z DEBUG New entry: cn=ADTrust Agents,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=ADTrust Agents,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG nestedgroup 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG ADTrust Agents 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG System accounts able to access trust information 2020-06-17T10:11:08Z DEBUG member: 2020-06-17T10:11:08Z DEBUG cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=ADTrust Agents,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG nestedgroup 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG ADTrust Agents 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG System accounts able to access trust information 2020-06-17T10:11:08Z DEBUG member: 2020-06-17T10:11:08Z DEBUG cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG New entry: cn=trusts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=trusts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG trusts 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=trusts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG trusts 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=trusts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=trusts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG trusts 2020-06-17T10:11:08Z DEBUG add: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)' to aci, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2020-06-17T10:11:08Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2020-06-17T10:11:08Z DEBUG add: updated value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:08Z DEBUG add: '(target = "ldap:///cn=trusts,dc=lin,dc=test,dc=lan")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:08Z DEBUG add: updated value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=trusts,dc=lin,dc=test,dc=lan")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:08Z DEBUG replace: updated value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=trusts,dc=lin,dc=test,dc=lan")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:08Z DEBUG replace: (target = "ldap:///cn=trusts,dc=lin,dc=test,dc=lan")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) not found, skipping 2020-06-17T10:11:08Z DEBUG add: '(target = "ldap:///cn=trusts,dc=lin,dc=test,dc=lan")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=trusts,dc=lin,dc=test,dc=lan")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:08Z DEBUG add: updated value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=trusts,dc=lin,dc=test,dc=lan")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=trusts,dc=lin,dc=test,dc=lan")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:08Z DEBUG add: '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=trusts,dc=lin,dc=test,dc=lan")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=trusts,dc=lin,dc=test,dc=lan")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:08Z DEBUG add: updated value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=trusts,dc=lin,dc=test,dc=lan")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=trusts,dc=lin,dc=test,dc=lan")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=trusts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG trusts 2020-06-17T10:11:08Z DEBUG aci: 2020-06-17T10:11:08Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2020-06-17T10:11:08Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (target = "ldap:///cn=trusts,dc=lin,dc=test,dc=lan")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (target = "ldap:///cn=trusts,dc=lin,dc=test,dc=lan")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG [(2, 'aci', ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=trusts,dc=lin,dc=test,dc=lan")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///cn=trusts,dc=lin,dc=test,dc=lan")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:11:08Z DEBUG Updated 1 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG domain 2020-06-17T10:11:08Z DEBUG pilotObject 2020-06-17T10:11:08Z DEBUG domainRelatedObject 2020-06-17T10:11:08Z DEBUG nisDomainObject 2020-06-17T10:11:08Z DEBUG dc: 2020-06-17T10:11:08Z DEBUG lin 2020-06-17T10:11:08Z DEBUG info: 2020-06-17T10:11:08Z DEBUG IPA V2.0 2020-06-17T10:11:08Z DEBUG nisDomain: 2020-06-17T10:11:08Z DEBUG lin.test.lan 2020-06-17T10:11:08Z DEBUG associatedDomain: 2020-06-17T10:11:08Z DEBUG lin.test.lan 2020-06-17T10:11:08Z DEBUG aci: 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:11:08Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:08Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:08Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:11:08Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:11:08Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:08Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:08Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:11:08Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:08Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG add: '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:08Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:08Z DEBUG remove: '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read NT passwords"; allow (read) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:08Z DEBUG remove: '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read NT passwords"; allow (read) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)' not in aci 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG domain 2020-06-17T10:11:08Z DEBUG pilotObject 2020-06-17T10:11:08Z DEBUG domainRelatedObject 2020-06-17T10:11:08Z DEBUG nisDomainObject 2020-06-17T10:11:08Z DEBUG dc: 2020-06-17T10:11:08Z DEBUG lin 2020-06-17T10:11:08Z DEBUG info: 2020-06-17T10:11:08Z DEBUG IPA V2.0 2020-06-17T10:11:08Z DEBUG nisDomain: 2020-06-17T10:11:08Z DEBUG lin.test.lan 2020-06-17T10:11:08Z DEBUG associatedDomain: 2020-06-17T10:11:08Z DEBUG lin.test.lan 2020-06-17T10:11:08Z DEBUG aci: 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:11:08Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:08Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:08Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:11:08Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:11:08Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:08Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:08Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:11:08Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:08Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG [(0, 'aci', ['(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)'])] 2020-06-17T10:11:08Z DEBUG Updated 1 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG services 2020-06-17T10:11:08Z DEBUG aci: 2020-06-17T10:11:08Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-17T10:11:08Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG add: '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=lin,dc=test,dc=lan" or userattr="managedby#SELFDN";)' to aci, current value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:08Z DEBUG add: updated value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=lin,dc=test,dc=lan" or userattr="managedby#SELFDN";)'] 2020-06-17T10:11:08Z DEBUG add: '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=lin,dc=test,dc=lan" or userattr="managedby#SELFDN";)' to aci, current value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=lin,dc=test,dc=lan" or userattr="managedby#SELFDN";)'] 2020-06-17T10:11:08Z DEBUG add: updated value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=lin,dc=test,dc=lan" or userattr="managedby#SELFDN";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=lin,dc=test,dc=lan" or userattr="managedby#SELFDN";)'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG services 2020-06-17T10:11:08Z DEBUG aci: 2020-06-17T10:11:08Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-17T10:11:08Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=lin,dc=test,dc=lan" or userattr="managedby#SELFDN";) 2020-06-17T10:11:08Z DEBUG (target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=lin,dc=test,dc=lan" or userattr="managedby#SELFDN";) 2020-06-17T10:11:08Z DEBUG [(0, 'aci', ['(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=lin,dc=test,dc=lan" or userattr="managedby#SELFDN";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=lin,dc=test,dc=lan")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=lin,dc=test,dc=lan" or userattr="managedby#SELFDN";)'])] 2020-06-17T10:11:08Z DEBUG Updated 1 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=ipaConfig,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=ipaConfig,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG ipaGuiConfig 2020-06-17T10:11:08Z DEBUG ipaConfigObject 2020-06-17T10:11:08Z DEBUG ipaUserAuthTypeClass 2020-06-17T10:11:08Z DEBUG ipaNameResolutionData 2020-06-17T10:11:08Z DEBUG ipaUserSearchFields: 2020-06-17T10:11:08Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2020-06-17T10:11:08Z DEBUG ipaGroupSearchFields: 2020-06-17T10:11:08Z DEBUG cn,description 2020-06-17T10:11:08Z DEBUG ipaSearchTimeLimit: 2020-06-17T10:11:08Z DEBUG 2 2020-06-17T10:11:08Z DEBUG ipaSearchRecordsLimit: 2020-06-17T10:11:08Z DEBUG 100 2020-06-17T10:11:08Z DEBUG ipaHomesRootDir: 2020-06-17T10:11:08Z DEBUG /home 2020-06-17T10:11:08Z DEBUG ipaDefaultLoginShell: 2020-06-17T10:11:08Z DEBUG /bin/sh 2020-06-17T10:11:08Z DEBUG ipaDefaultPrimaryGroup: 2020-06-17T10:11:08Z DEBUG ipausers 2020-06-17T10:11:08Z DEBUG ipaMaxUsernameLength: 2020-06-17T10:11:08Z DEBUG 32 2020-06-17T10:11:08Z DEBUG ipaMaxHostnameLength: 2020-06-17T10:11:08Z DEBUG 64 2020-06-17T10:11:08Z DEBUG ipaPwdExpAdvNotify: 2020-06-17T10:11:08Z DEBUG 4 2020-06-17T10:11:08Z DEBUG ipaGroupObjectClasses: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG nestedgroup 2020-06-17T10:11:08Z DEBUG ipausergroup 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG ipaUserObjectClasses: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG person 2020-06-17T10:11:08Z DEBUG organizationalperson 2020-06-17T10:11:08Z DEBUG inetorgperson 2020-06-17T10:11:08Z DEBUG inetuser 2020-06-17T10:11:08Z DEBUG posixaccount 2020-06-17T10:11:08Z DEBUG krbprincipalaux 2020-06-17T10:11:08Z DEBUG krbticketpolicyaux 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG ipasshuser 2020-06-17T10:11:08Z DEBUG ipaDefaultEmailDomain: 2020-06-17T10:11:08Z DEBUG lin.test.lan 2020-06-17T10:11:08Z DEBUG ipaMigrationEnabled: 2020-06-17T10:11:08Z DEBUG FALSE 2020-06-17T10:11:08Z DEBUG ipaConfigString: 2020-06-17T10:11:08Z DEBUG AllowNThash 2020-06-17T10:11:08Z DEBUG KDC:Disable Last Success 2020-06-17T10:11:08Z DEBUG ipaSELinuxUserMapOrder: 2020-06-17T10:11:08Z DEBUG guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$sysadm_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 2020-06-17T10:11:08Z DEBUG ipaSELinuxUserMapDefault: 2020-06-17T10:11:08Z DEBUG unconfined_u:s0-s0:c0.c1023 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG ipaConfig 2020-06-17T10:11:08Z DEBUG ipaCertificateSubjectBase: 2020-06-17T10:11:08Z DEBUG O=LIN.TEST.LAN 2020-06-17T10:11:08Z DEBUG addifnew: 'MS-PAC' to ipaKrbAuthzData, current value [] 2020-06-17T10:11:08Z DEBUG addifnew: set ipaKrbAuthzData to ['MS-PAC'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=ipaConfig,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG ipaGuiConfig 2020-06-17T10:11:08Z DEBUG ipaConfigObject 2020-06-17T10:11:08Z DEBUG ipaUserAuthTypeClass 2020-06-17T10:11:08Z DEBUG ipaNameResolutionData 2020-06-17T10:11:08Z DEBUG ipaUserSearchFields: 2020-06-17T10:11:08Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2020-06-17T10:11:08Z DEBUG ipaGroupSearchFields: 2020-06-17T10:11:08Z DEBUG cn,description 2020-06-17T10:11:08Z DEBUG ipaSearchTimeLimit: 2020-06-17T10:11:08Z DEBUG 2 2020-06-17T10:11:08Z DEBUG ipaSearchRecordsLimit: 2020-06-17T10:11:08Z DEBUG 100 2020-06-17T10:11:08Z DEBUG ipaHomesRootDir: 2020-06-17T10:11:08Z DEBUG /home 2020-06-17T10:11:08Z DEBUG ipaDefaultLoginShell: 2020-06-17T10:11:08Z DEBUG /bin/sh 2020-06-17T10:11:08Z DEBUG ipaDefaultPrimaryGroup: 2020-06-17T10:11:08Z DEBUG ipausers 2020-06-17T10:11:08Z DEBUG ipaMaxUsernameLength: 2020-06-17T10:11:08Z DEBUG 32 2020-06-17T10:11:08Z DEBUG ipaMaxHostnameLength: 2020-06-17T10:11:08Z DEBUG 64 2020-06-17T10:11:08Z DEBUG ipaPwdExpAdvNotify: 2020-06-17T10:11:08Z DEBUG 4 2020-06-17T10:11:08Z DEBUG ipaGroupObjectClasses: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG nestedgroup 2020-06-17T10:11:08Z DEBUG ipausergroup 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG ipaUserObjectClasses: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG person 2020-06-17T10:11:08Z DEBUG organizationalperson 2020-06-17T10:11:08Z DEBUG inetorgperson 2020-06-17T10:11:08Z DEBUG inetuser 2020-06-17T10:11:08Z DEBUG posixaccount 2020-06-17T10:11:08Z DEBUG krbprincipalaux 2020-06-17T10:11:08Z DEBUG krbticketpolicyaux 2020-06-17T10:11:08Z DEBUG ipaobject 2020-06-17T10:11:08Z DEBUG ipasshuser 2020-06-17T10:11:08Z DEBUG ipaDefaultEmailDomain: 2020-06-17T10:11:08Z DEBUG lin.test.lan 2020-06-17T10:11:08Z DEBUG ipaMigrationEnabled: 2020-06-17T10:11:08Z DEBUG FALSE 2020-06-17T10:11:08Z DEBUG ipaConfigString: 2020-06-17T10:11:08Z DEBUG AllowNThash 2020-06-17T10:11:08Z DEBUG KDC:Disable Last Success 2020-06-17T10:11:08Z DEBUG ipaSELinuxUserMapOrder: 2020-06-17T10:11:08Z DEBUG guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$sysadm_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 2020-06-17T10:11:08Z DEBUG ipaSELinuxUserMapDefault: 2020-06-17T10:11:08Z DEBUG unconfined_u:s0-s0:c0.c1023 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG ipaConfig 2020-06-17T10:11:08Z DEBUG ipaCertificateSubjectBase: 2020-06-17T10:11:08Z DEBUG O=LIN.TEST.LAN 2020-06-17T10:11:08Z DEBUG ipaKrbAuthzData: 2020-06-17T10:11:08Z DEBUG MS-PAC 2020-06-17T10:11:08Z DEBUG [(2, 'ipaKrbAuthzData', ['MS-PAC'])] 2020-06-17T10:11:08Z DEBUG Updated 1 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/60-trusts.update 0.125 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/61-trusts-s4u2proxy.update' 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG groupOfPrincipals 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG ipa-cifs-delegation-targets 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG groupOfPrincipals 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG ipa-cifs-delegation-targets 2020-06-17T10:11:08Z DEBUG [] 2020-06-17T10:11:08Z DEBUG Updated 0 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG ipaKrb5DelegationACL 2020-06-17T10:11:08Z DEBUG groupOfPrincipals 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG ipa-http-delegation 2020-06-17T10:11:08Z DEBUG memberPrincipal: 2020-06-17T10:11:08Z DEBUG HTTP/freeipaserver.lin.test.lan@LIN.TEST.LAN 2020-06-17T10:11:08Z DEBUG ipaAllowedTarget: 2020-06-17T10:11:08Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG add: 'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan' to ipaAllowedTarget, current value ['cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan', 'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: updated value ['cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan', 'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG ipaKrb5DelegationACL 2020-06-17T10:11:08Z DEBUG groupOfPrincipals 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG ipa-http-delegation 2020-06-17T10:11:08Z DEBUG memberPrincipal: 2020-06-17T10:11:08Z DEBUG HTTP/freeipaserver.lin.test.lan@LIN.TEST.LAN 2020-06-17T10:11:08Z DEBUG ipaAllowedTarget: 2020-06-17T10:11:08Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG [] 2020-06-17T10:11:08Z DEBUG Updated 0 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/61-trusts-s4u2proxy.update 0.005 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/62-ranges.update' 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=ranges,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=ranges,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG ranges 2020-06-17T10:11:08Z DEBUG aci: 2020-06-17T10:11:08Z DEBUG (target = "ldap:///cn=*,cn=ranges,cn=etc,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=ranges,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG ranges 2020-06-17T10:11:08Z DEBUG aci: 2020-06-17T10:11:08Z DEBUG (target = "ldap:///cn=*,cn=ranges,cn=etc,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@LIN.TEST.LAN,cn=services,cn=accounts,dc=lin,dc=test,dc=lan" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG [] 2020-06-17T10:11:08Z DEBUG Updated 0 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=IPA Range-Check,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=IPA Range-Check,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG IPA Range-Check 2020-06-17T10:11:08Z DEBUG nsslapd-basedn: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:08Z DEBUG database 2020-06-17T10:11:08Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:08Z DEBUG Check if newly added or modified ID ranges do not overlap with existing ones 2020-06-17T10:11:08Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:08Z DEBUG on 2020-06-17T10:11:08Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:08Z DEBUG IPA ID range check plugin 2020-06-17T10:11:08Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:08Z DEBUG ipa_range_check_init 2020-06-17T10:11:08Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:08Z DEBUG libipa_range_check 2020-06-17T10:11:08Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:08Z DEBUG preoperation 2020-06-17T10:11:08Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:08Z DEBUG FreeIPA project 2020-06-17T10:11:08Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:08Z DEBUG FreeIPA/1.0 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsSlapdPlugin 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=IPA Range-Check,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG IPA Range-Check 2020-06-17T10:11:08Z DEBUG nsslapd-basedn: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-17T10:11:08Z DEBUG database 2020-06-17T10:11:08Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:08Z DEBUG Check if newly added or modified ID ranges do not overlap with existing ones 2020-06-17T10:11:08Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:08Z DEBUG on 2020-06-17T10:11:08Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:08Z DEBUG IPA ID range check plugin 2020-06-17T10:11:08Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:08Z DEBUG ipa_range_check_init 2020-06-17T10:11:08Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:08Z DEBUG libipa_range_check 2020-06-17T10:11:08Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:08Z DEBUG preoperation 2020-06-17T10:11:08Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:08Z DEBUG FreeIPA project 2020-06-17T10:11:08Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:08Z DEBUG FreeIPA/1.0 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsSlapdPlugin 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG [] 2020-06-17T10:11:08Z DEBUG Updated 0 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG Posix IDs 2020-06-17T10:11:08Z DEBUG dnaExcludeScope: 2020-06-17T10:11:08Z DEBUG cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG dnaFilter: 2020-06-17T10:11:08Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2020-06-17T10:11:08Z DEBUG dnaMagicRegen: 2020-06-17T10:11:08Z DEBUG -1 2020-06-17T10:11:08Z DEBUG dnaMaxValue: 2020-06-17T10:11:08Z DEBUG 363799999 2020-06-17T10:11:08Z DEBUG dnaNextValue: 2020-06-17T10:11:08Z DEBUG 363600000 2020-06-17T10:11:08Z DEBUG dnaScope: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG dnaSharedCfgDN: 2020-06-17T10:11:08Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG dnaThreshold: 2020-06-17T10:11:08Z DEBUG 500 2020-06-17T10:11:08Z DEBUG dnaType: 2020-06-17T10:11:08Z DEBUG uidNumber 2020-06-17T10:11:08Z DEBUG gidNumber 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG aci: 2020-06-17T10:11:08Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG replace: (|(objectclass=posixAccount)(objectClass=posixGroup)) not found, skipping 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG Posix IDs 2020-06-17T10:11:08Z DEBUG dnaExcludeScope: 2020-06-17T10:11:08Z DEBUG cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG dnaFilter: 2020-06-17T10:11:08Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2020-06-17T10:11:08Z DEBUG dnaMagicRegen: 2020-06-17T10:11:08Z DEBUG -1 2020-06-17T10:11:08Z DEBUG dnaMaxValue: 2020-06-17T10:11:08Z DEBUG 363799999 2020-06-17T10:11:08Z DEBUG dnaNextValue: 2020-06-17T10:11:08Z DEBUG 363600000 2020-06-17T10:11:08Z DEBUG dnaScope: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG dnaSharedCfgDN: 2020-06-17T10:11:08Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG dnaThreshold: 2020-06-17T10:11:08Z DEBUG 500 2020-06-17T10:11:08Z DEBUG dnaType: 2020-06-17T10:11:08Z DEBUG uidNumber 2020-06-17T10:11:08Z DEBUG gidNumber 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG aci: 2020-06-17T10:11:08Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG [] 2020-06-17T10:11:08Z DEBUG Updated 0 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/62-ranges.update 0.012 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/71-idviews-sasl-mapping.update' 2020-06-17T10:11:08Z DEBUG New entry: cn=ID Overridden Principal,cn=mapping,cn=sasl,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=ID Overridden Principal,cn=mapping,cn=sasl,cn=config 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG ID Overridden Principal 2020-06-17T10:11:08Z DEBUG nsSaslMapBaseDNTemplate: 2020-06-17T10:11:08Z DEBUG cn=default trust view,cn=views,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG nsSaslMapFilterTemplate: 2020-06-17T10:11:08Z DEBUG (&(ipaoriginaluid=\1@\2)(objectclass=ipaUserOverride)) 2020-06-17T10:11:08Z DEBUG nsSaslMapPriority: 2020-06-17T10:11:08Z DEBUG 20 2020-06-17T10:11:08Z DEBUG nsSaslMapRegexString: 2020-06-17T10:11:08Z DEBUG \(.*\)@\(.*\) 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsSaslMapping 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=ID Overridden Principal,cn=mapping,cn=sasl,cn=config 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG ID Overridden Principal 2020-06-17T10:11:08Z DEBUG nsSaslMapBaseDNTemplate: 2020-06-17T10:11:08Z DEBUG cn=default trust view,cn=views,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG nsSaslMapFilterTemplate: 2020-06-17T10:11:08Z DEBUG (&(ipaoriginaluid=\1@\2)(objectclass=ipaUserOverride)) 2020-06-17T10:11:08Z DEBUG nsSaslMapPriority: 2020-06-17T10:11:08Z DEBUG 20 2020-06-17T10:11:08Z DEBUG nsSaslMapRegexString: 2020-06-17T10:11:08Z DEBUG \(.*\)@\(.*\) 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsSaslMapping 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/71-idviews-sasl-mapping.update 0.010 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/71-idviews.update' 2020-06-17T10:11:08Z DEBUG New entry: cn=views,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=views,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG views 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=views,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG views 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/71-idviews.update 0.005 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/72-domainlevels.update' 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=Domain Level,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=Domain Level,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG ipaDomainLevelConfig 2020-06-17T10:11:08Z DEBUG ipaConfigObject 2020-06-17T10:11:08Z DEBUG ipaDomainLevel: 2020-06-17T10:11:08Z DEBUG 1 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG Domain Level 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=Domain Level,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG ipaDomainLevelConfig 2020-06-17T10:11:08Z DEBUG ipaConfigObject 2020-06-17T10:11:08Z DEBUG ipaDomainLevel: 2020-06-17T10:11:08Z DEBUG 1 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG Domain Level 2020-06-17T10:11:08Z DEBUG [] 2020-06-17T10:11:08Z DEBUG Updated 0 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=freeipaserver.lin.test.lan,cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=freeipaserver.lin.test.lan,cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG ipaReplTopoManagedServer 2020-06-17T10:11:08Z DEBUG ipaConfigObject 2020-06-17T10:11:08Z DEBUG ipaSupportedDomainLevelConfig 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:11:08Z DEBUG ipaReplTopoManagedSuffix: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG ipaMinDomainLevel: 2020-06-17T10:11:08Z DEBUG 1 2020-06-17T10:11:08Z DEBUG ipaMaxDomainLevel: 2020-06-17T10:11:08Z DEBUG 1 2020-06-17T10:11:08Z DEBUG add: 'ipaConfigObject' to objectClass, current value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig'] 2020-06-17T10:11:08Z DEBUG add: updated value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaSupportedDomainLevelConfig', 'ipaConfigObject'] 2020-06-17T10:11:08Z DEBUG add: 'ipaSupportedDomainLevelConfig' to objectClass, current value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaSupportedDomainLevelConfig', 'ipaConfigObject'] 2020-06-17T10:11:08Z DEBUG add: updated value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig'] 2020-06-17T10:11:08Z DEBUG only: set ipaMinDomainLevel to '1', current value ['1'] 2020-06-17T10:11:08Z DEBUG only: updated value ['1'] 2020-06-17T10:11:08Z DEBUG only: set ipaMaxDomainLevel to '1', current value ['1'] 2020-06-17T10:11:08Z DEBUG only: updated value ['1'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=freeipaserver.lin.test.lan,cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG ipaReplTopoManagedServer 2020-06-17T10:11:08Z DEBUG ipaConfigObject 2020-06-17T10:11:08Z DEBUG ipaSupportedDomainLevelConfig 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:11:08Z DEBUG ipaReplTopoManagedSuffix: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG ipaMinDomainLevel: 2020-06-17T10:11:08Z DEBUG 1 2020-06-17T10:11:08Z DEBUG ipaMaxDomainLevel: 2020-06-17T10:11:08Z DEBUG 1 2020-06-17T10:11:08Z DEBUG [] 2020-06-17T10:11:08Z DEBUG Updated 0 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/72-domainlevels.update 0.006 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/73-certmap.update' 2020-06-17T10:11:08Z DEBUG New entry: cn=certmap,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=certmap,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectclass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG ipaCertMapConfigObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG certmap 2020-06-17T10:11:08Z DEBUG ipaCertMapPromptUsername: 2020-06-17T10:11:08Z DEBUG FALSE 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=certmap,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectclass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG ipaCertMapConfigObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG certmap 2020-06-17T10:11:08Z DEBUG ipaCertMapPromptUsername: 2020-06-17T10:11:08Z DEBUG FALSE 2020-06-17T10:11:08Z DEBUG New entry: cn=certmaprules,cn=certmap,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=certmaprules,cn=certmap,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectclass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG certmaprules 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=certmaprules,cn=certmap,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectclass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG certmaprules 2020-06-17T10:11:08Z DEBUG New entry: cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG nestedgroup 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG Certificate Identity Mapping Administrators 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG Certificate Identity Mapping Administrators 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG groupofnames 2020-06-17T10:11:08Z DEBUG nestedgroup 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG Certificate Identity Mapping Administrators 2020-06-17T10:11:08Z DEBUG description: 2020-06-17T10:11:08Z DEBUG Certificate Identity Mapping Administrators 2020-06-17T10:11:08Z DEBUG Updating existing entry: dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG domain 2020-06-17T10:11:08Z DEBUG pilotObject 2020-06-17T10:11:08Z DEBUG domainRelatedObject 2020-06-17T10:11:08Z DEBUG nisDomainObject 2020-06-17T10:11:08Z DEBUG dc: 2020-06-17T10:11:08Z DEBUG lin 2020-06-17T10:11:08Z DEBUG info: 2020-06-17T10:11:08Z DEBUG IPA V2.0 2020-06-17T10:11:08Z DEBUG nisDomain: 2020-06-17T10:11:08Z DEBUG lin.test.lan 2020-06-17T10:11:08Z DEBUG associatedDomain: 2020-06-17T10:11:08Z DEBUG lin.test.lan 2020-06-17T10:11:08Z DEBUG aci: 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:11:08Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:08Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:08Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:11:08Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:11:08Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:08Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:08Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:11:08Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:08Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG add: '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:08Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG domain 2020-06-17T10:11:08Z DEBUG pilotObject 2020-06-17T10:11:08Z DEBUG domainRelatedObject 2020-06-17T10:11:08Z DEBUG nisDomainObject 2020-06-17T10:11:08Z DEBUG dc: 2020-06-17T10:11:08Z DEBUG lin 2020-06-17T10:11:08Z DEBUG info: 2020-06-17T10:11:08Z DEBUG IPA V2.0 2020-06-17T10:11:08Z DEBUG nisDomain: 2020-06-17T10:11:08Z DEBUG lin.test.lan 2020-06-17T10:11:08Z DEBUG associatedDomain: 2020-06-17T10:11:08Z DEBUG lin.test.lan 2020-06-17T10:11:08Z DEBUG aci: 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-17T10:11:08Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:08Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:08Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-17T10:11:08Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=lin,dc=test,dc=lan")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-17T10:11:08Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:08Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:08Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-17T10:11:08Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-17T10:11:08Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=lin,dc=test,dc=lan" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:08Z DEBUG [(0, 'aci', ['(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)'])] 2020-06-17T10:11:08Z DEBUG Updated 1 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/73-certmap.update 0.036 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/73-custodia.update' 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG custodia 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG custodia 2020-06-17T10:11:08Z DEBUG [] 2020-06-17T10:11:08Z DEBUG Updated 0 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG dogtag 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG dogtag 2020-06-17T10:11:08Z DEBUG [] 2020-06-17T10:11:08Z DEBUG Updated 0 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/73-custodia.update 0.004 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/73-winsync.update' 2020-06-17T10:11:08Z DEBUG New entry: uid=passsync,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: uid=passsync,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG addifexist: 'inetUser' to objectClass, current value [] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: uid=passsync,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/73-winsync.update 0.001 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/75-user-trust-attributes.update' 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG users 2020-06-17T10:11:08Z DEBUG add: '(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)' to aci, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:08Z DEBUG add: '(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "selfservice:Users can manage their SMB attributes";allow (write) userdn = "ldap:///self";)' to aci, current value ['(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)'] 2020-06-17T10:11:08Z DEBUG add: updated value ['(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "selfservice:Users can manage their SMB attributes";allow (write) userdn = "ldap:///self";)'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsContainer 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG users 2020-06-17T10:11:08Z DEBUG aci: 2020-06-17T10:11:08Z DEBUG (targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";) 2020-06-17T10:11:08Z DEBUG (targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "selfservice:Users can manage their SMB attributes";allow (write) userdn = "ldap:///self";) 2020-06-17T10:11:08Z DEBUG [(2, 'aci', ['(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan";)', '(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "selfservice:Users can manage their SMB attributes";allow (write) userdn = "ldap:///self";)'])] 2020-06-17T10:11:08Z DEBUG Updated 1 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/75-user-trust-attributes.update 0.005 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/80-schema_compat.update' 2020-06-17T10:11:08Z DEBUG New entry: cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectclass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsSlapdPlugin 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG Schema Compatibility 2020-06-17T10:11:08Z DEBUG nsslapd-pluginpath: 2020-06-17T10:11:08Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2020-06-17T10:11:08Z DEBUG nsslapd-plugininitfunc: 2020-06-17T10:11:08Z DEBUG schema_compat_plugin_init 2020-06-17T10:11:08Z DEBUG nsslapd-plugintype: 2020-06-17T10:11:08Z DEBUG object 2020-06-17T10:11:08Z DEBUG nsslapd-pluginenabled: 2020-06-17T10:11:08Z DEBUG on 2020-06-17T10:11:08Z DEBUG nsslapd-pluginid: 2020-06-17T10:11:08Z DEBUG schema-compat-plugin 2020-06-17T10:11:08Z DEBUG nsslapd-pluginprecedence: 2020-06-17T10:11:08Z DEBUG 40 2020-06-17T10:11:08Z DEBUG nsslapd-pluginversion: 2020-06-17T10:11:08Z DEBUG 0.8 2020-06-17T10:11:08Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:11:08Z DEBUG on 2020-06-17T10:11:08Z DEBUG nsslapd-pluginvendor: 2020-06-17T10:11:08Z DEBUG redhat.com 2020-06-17T10:11:08Z DEBUG nsslapd-plugindescription: 2020-06-17T10:11:08Z DEBUG Schema Compatibility Plugin 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectclass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsSlapdPlugin 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG Schema Compatibility 2020-06-17T10:11:08Z DEBUG nsslapd-pluginpath: 2020-06-17T10:11:08Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2020-06-17T10:11:08Z DEBUG nsslapd-plugininitfunc: 2020-06-17T10:11:08Z DEBUG schema_compat_plugin_init 2020-06-17T10:11:08Z DEBUG nsslapd-plugintype: 2020-06-17T10:11:08Z DEBUG object 2020-06-17T10:11:08Z DEBUG nsslapd-pluginenabled: 2020-06-17T10:11:08Z DEBUG on 2020-06-17T10:11:08Z DEBUG nsslapd-pluginid: 2020-06-17T10:11:08Z DEBUG schema-compat-plugin 2020-06-17T10:11:08Z DEBUG nsslapd-pluginprecedence: 2020-06-17T10:11:08Z DEBUG 40 2020-06-17T10:11:08Z DEBUG nsslapd-pluginversion: 2020-06-17T10:11:08Z DEBUG 0.8 2020-06-17T10:11:08Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:11:08Z DEBUG on 2020-06-17T10:11:08Z DEBUG nsslapd-pluginvendor: 2020-06-17T10:11:08Z DEBUG redhat.com 2020-06-17T10:11:08Z DEBUG nsslapd-plugindescription: 2020-06-17T10:11:08Z DEBUG Schema Compatibility Plugin 2020-06-17T10:11:08Z DEBUG New entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG users 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=users 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=users, cn=accounts, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG objectclass=posixAccount 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG uid=%{uid} 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=posixAccount 2020-06-17T10:11:08Z DEBUG gecos=%{cn} 2020-06-17T10:11:08Z DEBUG cn=%{cn} 2020-06-17T10:11:08Z DEBUG uidNumber=%{uidNumber} 2020-06-17T10:11:08Z DEBUG gidNumber=%{gidNumber} 2020-06-17T10:11:08Z DEBUG loginShell=%{loginShell} 2020-06-17T10:11:08Z DEBUG homeDirectory=%{homeDirectory} 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","") 2020-06-17T10:11:08Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-17T10:11:08Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG users 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=users 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=users, cn=accounts, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG objectclass=posixAccount 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG uid=%{uid} 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=posixAccount 2020-06-17T10:11:08Z DEBUG gecos=%{cn} 2020-06-17T10:11:08Z DEBUG cn=%{cn} 2020-06-17T10:11:08Z DEBUG uidNumber=%{uidNumber} 2020-06-17T10:11:08Z DEBUG gidNumber=%{gidNumber} 2020-06-17T10:11:08Z DEBUG loginShell=%{loginShell} 2020-06-17T10:11:08Z DEBUG homeDirectory=%{homeDirectory} 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","") 2020-06-17T10:11:08Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-17T10:11:08Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG New entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG groups 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=groups 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=groups, cn=accounts, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG objectclass=posixGroup 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG cn=%{cn} 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=posixGroup 2020-06-17T10:11:08Z DEBUG gidNumber=%{gidNumber} 2020-06-17T10:11:08Z DEBUG memberUid=%{memberUid} 2020-06-17T10:11:08Z DEBUG memberUid=%deref_r("member","uid") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","") 2020-06-17T10:11:08Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-17T10:11:08Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG groups 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=groups 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=groups, cn=accounts, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG objectclass=posixGroup 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG cn=%{cn} 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=posixGroup 2020-06-17T10:11:08Z DEBUG gidNumber=%{gidNumber} 2020-06-17T10:11:08Z DEBUG memberUid=%{memberUid} 2020-06-17T10:11:08Z DEBUG memberUid=%deref_r("member","uid") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","") 2020-06-17T10:11:08Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-17T10:11:08Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG New entry: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG add: 'top' to objectClass, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['top'] 2020-06-17T10:11:08Z DEBUG add: 'extensibleObject' to objectClass, current value ['top'] 2020-06-17T10:11:08Z DEBUG add: updated value ['top', 'extensibleObject'] 2020-06-17T10:11:08Z DEBUG add: 'ng' to cn, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['ng'] 2020-06-17T10:11:08Z DEBUG add: 'cn=compat, dc=lin,dc=test,dc=lan' to schema-compat-container-group, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['cn=compat, dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: 'cn=ng' to schema-compat-container-rdn, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['cn=ng'] 2020-06-17T10:11:08Z DEBUG add: 'yes' to schema-compat-check-access, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['yes'] 2020-06-17T10:11:08Z DEBUG add: 'cn=ng, cn=alt, dc=lin,dc=test,dc=lan' to schema-compat-search-base, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['cn=ng, cn=alt, dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: '(objectclass=ipaNisNetgroup)' to schema-compat-search-filter, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['(objectclass=ipaNisNetgroup)'] 2020-06-17T10:11:08Z DEBUG add: 'cn=%{cn}' to schema-compat-entry-rdn, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['cn=%{cn}'] 2020-06-17T10:11:08Z DEBUG add: 'objectclass=nisNetgroup' to schema-compat-entry-attribute, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=nisNetgroup'] 2020-06-17T10:11:08Z DEBUG add: 'memberNisNetgroup=%deref_r("member","cn")' to schema-compat-entry-attribute, current value ['objectclass=nisNetgroup'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=nisNetgroup', 'memberNisNetgroup=%deref_r("member","cn")'] 2020-06-17T10:11:08Z DEBUG add: 'nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-})' to schema-compat-entry-attribute, current value ['objectclass=nisNetgroup', 'memberNisNetgroup=%deref_r("member","cn")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=nisNetgroup', 'memberNisNetgroup=%deref_r("member","cn")', 'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","-",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","-"),%{nisDomainName:-})'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG ng 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=ng 2020-06-17T10:11:08Z DEBUG schema-compat-check-access: 2020-06-17T10:11:08Z DEBUG yes 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=ng, cn=alt, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG (objectclass=ipaNisNetgroup) 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG cn=%{cn} 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=nisNetgroup 2020-06-17T10:11:08Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2020-06-17T10:11:08Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-}) 2020-06-17T10:11:08Z DEBUG New entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG add: 'top' to objectClass, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['top'] 2020-06-17T10:11:08Z DEBUG add: 'extensibleObject' to objectClass, current value ['top'] 2020-06-17T10:11:08Z DEBUG add: updated value ['top', 'extensibleObject'] 2020-06-17T10:11:08Z DEBUG add: 'sudoers' to cn, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['sudoers'] 2020-06-17T10:11:08Z DEBUG add: 'ou=SUDOers, dc=lin,dc=test,dc=lan' to schema-compat-container-group, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['ou=SUDOers, dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: 'cn=sudorules, cn=sudo, dc=lin,dc=test,dc=lan' to schema-compat-search-base, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['cn=sudorules, cn=sudo, dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: '(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))' to schema-compat-search-filter, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))'] 2020-06-17T10:11:08Z DEBUG add: '%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")' to schema-compat-entry-rdn, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2020-06-17T10:11:08Z DEBUG add: 'objectclass=sudoRole' to schema-compat-entry-attribute, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole'] 2020-06-17T10:11:08Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoOption=%{ipaSudoOpt}' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG sudoers 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG ou=SUDOers, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=sudorules, cn=sudo, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=sudoRole 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2020-06-17T10:11:08Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2020-06-17T10:11:08Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2020-06-17T10:11:08Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2020-06-17T10:11:08Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2020-06-17T10:11:08Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoOption=%{ipaSudoOpt} 2020-06-17T10:11:08Z DEBUG New entry: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG computers 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=computers 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=computers, cn=accounts, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG cn=%first("%{fqdn}") 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=device 2020-06-17T10:11:08Z DEBUG objectclass=ieee802Device 2020-06-17T10:11:08Z DEBUG cn=%{fqdn} 2020-06-17T10:11:08Z DEBUG macAddress=%{macAddress} 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG computers 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=computers 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=computers, cn=accounts, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG cn=%first("%{fqdn}") 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=device 2020-06-17T10:11:08Z DEBUG objectclass=ieee802Device 2020-06-17T10:11:08Z DEBUG cn=%{fqdn} 2020-06-17T10:11:08Z DEBUG macAddress=%{macAddress} 2020-06-17T10:11:08Z DEBUG Updating existing entry: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG VLV Request Control 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG directoryServerFeature 2020-06-17T10:11:08Z DEBUG oid: 2020-06-17T10:11:08Z DEBUG 2.16.840.1.113730.3.4.9 2020-06-17T10:11:08Z DEBUG aci: 2020-06-17T10:11:08Z DEBUG (targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";) 2020-06-17T10:11:08Z DEBUG only: set aci to '(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )', current value ['(targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";)'] 2020-06-17T10:11:08Z DEBUG only: updated value ['(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG VLV Request Control 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG directoryServerFeature 2020-06-17T10:11:08Z DEBUG oid: 2020-06-17T10:11:08Z DEBUG 2.16.840.1.113730.3.4.9 2020-06-17T10:11:08Z DEBUG aci: 2020-06-17T10:11:08Z DEBUG (targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; ) 2020-06-17T10:11:08Z DEBUG [(1, 'aci', ['(targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";)']), (0, 'aci', ['(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )'])] 2020-06-17T10:11:08Z DEBUG Updated 1 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG sudoers 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG ou=SUDOers, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=sudorules, cn=sudo, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=sudoRole 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2020-06-17T10:11:08Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2020-06-17T10:11:08Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2020-06-17T10:11:08Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2020-06-17T10:11:08Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2020-06-17T10:11:08Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoOption=%{ipaSudoOpt} 2020-06-17T10:11:08Z DEBUG only: set schema-compat-entry-rdn to '%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")', current value ['%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2020-06-17T10:11:08Z DEBUG only: updated value ['%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2020-06-17T10:11:08Z DEBUG remove: 'sudoRunAsGroup=%deref("ipaSudoRunAs","cn")' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2020-06-17T10:11:08Z DEBUG remove: 'sudoRunAsGroup=%deref("ipaSudoRunAs","cn")' not in schema-compat-entry-attribute 2020-06-17T10:11:08Z DEBUG remove: 'sudoRunAsUser=%{ipaSudoRunAsExtUser}' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2020-06-17T10:11:08Z DEBUG remove: 'sudoRunAsUser=%{ipaSudoRunAsExtUser}' not in schema-compat-entry-attribute 2020-06-17T10:11:08Z DEBUG remove: 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2020-06-17T10:11:08Z DEBUG remove: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2020-06-17T10:11:08Z DEBUG remove: 'sudoRunAsUser=%deref("ipaSudoRunAs","uid")' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2020-06-17T10:11:08Z DEBUG remove: 'sudoRunAsUser=%deref("ipaSudoRunAs","uid")' not in schema-compat-entry-attribute 2020-06-17T10:11:08Z DEBUG remove: 'sudoRunAsGroup=%{ipaSudoRunAsExtGroup}' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2020-06-17T10:11:08Z DEBUG remove: 'sudoRunAsGroup=%{ipaSudoRunAsExtGroup}' not in schema-compat-entry-attribute 2020-06-17T10:11:08Z DEBUG remove: 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2020-06-17T10:11:08Z DEBUG remove: 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")' not in schema-compat-entry-attribute 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG sudoers 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG ou=SUDOers, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=sudorules, cn=sudo, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=sudoRole 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2020-06-17T10:11:08Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2020-06-17T10:11:08Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2020-06-17T10:11:08Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2020-06-17T10:11:08Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoOption=%{ipaSudoOpt} 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2020-06-17T10:11:08Z DEBUG [] 2020-06-17T10:11:08Z DEBUG Updated 0 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG sudoers 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG ou=SUDOers, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=sudorules, cn=sudo, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=sudoRole 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2020-06-17T10:11:08Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2020-06-17T10:11:08Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2020-06-17T10:11:08Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2020-06-17T10:11:08Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2020-06-17T10:11:08Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoOption=%{ipaSudoOpt} 2020-06-17T10:11:08Z DEBUG add: 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2020-06-17T10:11:08Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2020-06-17T10:11:08Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2020-06-17T10:11:08Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2020-06-17T10:11:08Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2020-06-17T10:11:08Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2020-06-17T10:11:08Z DEBUG add: 'dc=lin,dc=test,dc=lan' to schema-compat-restrict-subtree, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value ['dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: updated value ['dc=lin,dc=test,dc=lan', 'cn=Schema Compatibility,cn=plugins,cn=config'] 2020-06-17T10:11:08Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan' to schema-compat-ignore-subtree, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan' to schema-compat-ignore-subtree, current value ['cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan', 'cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG sudoers 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG ou=SUDOers, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=sudorules, cn=sudo, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=sudoRole 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2020-06-17T10:11:08Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2020-06-17T10:11:08Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2020-06-17T10:11:08Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2020-06-17T10:11:08Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoOption=%{ipaSudoOpt} 2020-06-17T10:11:08Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-17T10:11:08Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2020-06-17T10:11:08Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG schema-compat-restrict-subtree: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG schema-compat-ignore-subtree: 2020-06-17T10:11:08Z DEBUG cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG [(2, 'schema-compat-ignore-subtree', ['cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan', 'cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan']), (0, 'schema-compat-entry-attribute', ['sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")']), (2, 'schema-compat-restrict-subtree', ['dc=lin,dc=test,dc=lan', 'cn=Schema Compatibility,cn=plugins,cn=config'])] 2020-06-17T10:11:08Z DEBUG Updated 1 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG ng 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=ng 2020-06-17T10:11:08Z DEBUG schema-compat-check-access: 2020-06-17T10:11:08Z DEBUG yes 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=ng, cn=alt, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG (objectclass=ipaNisNetgroup) 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG cn=%{cn} 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=nisNetgroup 2020-06-17T10:11:08Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2020-06-17T10:11:08Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-}) 2020-06-17T10:11:08Z DEBUG replace: updated value ['objectclass=nisNetgroup', 'memberNisNetgroup=%deref_r("member","cn")', 'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})'] 2020-06-17T10:11:08Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2020-06-17T10:11:08Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2020-06-17T10:11:08Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2020-06-17T10:11:08Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2020-06-17T10:11:08Z DEBUG add: 'dc=lin,dc=test,dc=lan' to schema-compat-restrict-subtree, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value ['dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: updated value ['dc=lin,dc=test,dc=lan', 'cn=Schema Compatibility,cn=plugins,cn=config'] 2020-06-17T10:11:08Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan' to schema-compat-ignore-subtree, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan' to schema-compat-ignore-subtree, current value ['cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan', 'cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG ng 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=ng 2020-06-17T10:11:08Z DEBUG schema-compat-check-access: 2020-06-17T10:11:08Z DEBUG yes 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=ng, cn=alt, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG (objectclass=ipaNisNetgroup) 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG cn=%{cn} 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=nisNetgroup 2020-06-17T10:11:08Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2020-06-17T10:11:08Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","%ifeq(\"hostCategory\",\"all\",\"\",\"-\")",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","%ifeq(\"userCategory\",\"all\",\"\",\"-\")"),%{nisDomainName:-}) 2020-06-17T10:11:08Z DEBUG schema-compat-restrict-subtree: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG schema-compat-ignore-subtree: 2020-06-17T10:11:08Z DEBUG cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG [(2, 'schema-compat-ignore-subtree', ['cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan', 'cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan']), (1, 'schema-compat-entry-attribute', ['nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","-",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","-"),%{nisDomainName:-})']), (0, 'schema-compat-entry-attribute', ['nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})']), (2, 'schema-compat-restrict-subtree', ['dc=lin,dc=test,dc=lan', 'cn=Schema Compatibility,cn=plugins,cn=config'])] 2020-06-17T10:11:08Z DEBUG Updated 1 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG computers 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=computers 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=computers, cn=accounts, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG cn=%first("%{fqdn}") 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=device 2020-06-17T10:11:08Z DEBUG objectclass=ieee802Device 2020-06-17T10:11:08Z DEBUG cn=%{fqdn} 2020-06-17T10:11:08Z DEBUG macAddress=%{macAddress} 2020-06-17T10:11:08Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2020-06-17T10:11:08Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2020-06-17T10:11:08Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2020-06-17T10:11:08Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2020-06-17T10:11:08Z DEBUG add: 'dc=lin,dc=test,dc=lan' to schema-compat-restrict-subtree, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value ['dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: updated value ['dc=lin,dc=test,dc=lan', 'cn=Schema Compatibility,cn=plugins,cn=config'] 2020-06-17T10:11:08Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan' to schema-compat-ignore-subtree, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan' to schema-compat-ignore-subtree, current value ['cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan', 'cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG computers 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=computers 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=computers, cn=accounts, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG cn=%first("%{fqdn}") 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=device 2020-06-17T10:11:08Z DEBUG objectclass=ieee802Device 2020-06-17T10:11:08Z DEBUG cn=%{fqdn} 2020-06-17T10:11:08Z DEBUG macAddress=%{macAddress} 2020-06-17T10:11:08Z DEBUG schema-compat-restrict-subtree: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG schema-compat-ignore-subtree: 2020-06-17T10:11:08Z DEBUG cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG [(2, 'schema-compat-ignore-subtree', ['cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan', 'cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan']), (2, 'schema-compat-restrict-subtree', ['dc=lin,dc=test,dc=lan', 'cn=Schema Compatibility,cn=plugins,cn=config'])] 2020-06-17T10:11:08Z DEBUG Updated 1 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG sudoers 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG ou=SUDOers, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=sudorules, cn=sudo, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=sudoRole 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2020-06-17T10:11:08Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2020-06-17T10:11:08Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2020-06-17T10:11:08Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2020-06-17T10:11:08Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2020-06-17T10:11:08Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoOption=%{ipaSudoOpt} 2020-06-17T10:11:08Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2020-06-17T10:11:08Z DEBUG schema-compat-ignore-subtree: 2020-06-17T10:11:08Z DEBUG cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-restrict-subtree: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG add: 'sudoOrder=%{sudoOrder}' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoOrder=%{sudoOrder}'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG sudoers 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG ou=SUDOers, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=sudorules, cn=sudo, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=sudoRole 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2020-06-17T10:11:08Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2020-06-17T10:11:08Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2020-06-17T10:11:08Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2020-06-17T10:11:08Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-17T10:11:08Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2020-06-17T10:11:08Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-17T10:11:08Z DEBUG sudoOption=%{ipaSudoOpt} 2020-06-17T10:11:08Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2020-06-17T10:11:08Z DEBUG sudoOrder=%{sudoOrder} 2020-06-17T10:11:08Z DEBUG schema-compat-ignore-subtree: 2020-06-17T10:11:08Z DEBUG cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-restrict-subtree: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG [(0, 'schema-compat-entry-attribute', ['sudoOrder=%{sudoOrder}'])] 2020-06-17T10:11:08Z DEBUG Updated 1 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG users 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=users 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=users, cn=accounts, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG objectclass=posixAccount 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG uid=%{uid} 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=posixAccount 2020-06-17T10:11:08Z DEBUG gecos=%{cn} 2020-06-17T10:11:08Z DEBUG cn=%{cn} 2020-06-17T10:11:08Z DEBUG uidNumber=%{uidNumber} 2020-06-17T10:11:08Z DEBUG gidNumber=%{gidNumber} 2020-06-17T10:11:08Z DEBUG loginShell=%{loginShell} 2020-06-17T10:11:08Z DEBUG homeDirectory=%{homeDirectory} 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","") 2020-06-17T10:11:08Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-17T10:11:08Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2020-06-17T10:11:08Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2020-06-17T10:11:08Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2020-06-17T10:11:08Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2020-06-17T10:11:08Z DEBUG add: 'dc=lin,dc=test,dc=lan' to schema-compat-restrict-subtree, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value ['dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: updated value ['dc=lin,dc=test,dc=lan', 'cn=Schema Compatibility,cn=plugins,cn=config'] 2020-06-17T10:11:08Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan' to schema-compat-ignore-subtree, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan' to schema-compat-ignore-subtree, current value ['cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan', 'cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG users 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=users 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=users, cn=accounts, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG objectclass=posixAccount 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG uid=%{uid} 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=posixAccount 2020-06-17T10:11:08Z DEBUG gecos=%{cn} 2020-06-17T10:11:08Z DEBUG cn=%{cn} 2020-06-17T10:11:08Z DEBUG uidNumber=%{uidNumber} 2020-06-17T10:11:08Z DEBUG gidNumber=%{gidNumber} 2020-06-17T10:11:08Z DEBUG loginShell=%{loginShell} 2020-06-17T10:11:08Z DEBUG homeDirectory=%{homeDirectory} 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","") 2020-06-17T10:11:08Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-17T10:11:08Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG schema-compat-restrict-subtree: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG schema-compat-ignore-subtree: 2020-06-17T10:11:08Z DEBUG cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG [(2, 'schema-compat-ignore-subtree', ['cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan', 'cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan']), (2, 'schema-compat-restrict-subtree', ['dc=lin,dc=test,dc=lan', 'cn=Schema Compatibility,cn=plugins,cn=config'])] 2020-06-17T10:11:08Z DEBUG Updated 1 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG groups 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=groups 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=groups, cn=accounts, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG objectclass=posixGroup 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG cn=%{cn} 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=posixGroup 2020-06-17T10:11:08Z DEBUG gidNumber=%{gidNumber} 2020-06-17T10:11:08Z DEBUG memberUid=%{memberUid} 2020-06-17T10:11:08Z DEBUG memberUid=%deref_r("member","uid") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","") 2020-06-17T10:11:08Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-17T10:11:08Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2020-06-17T10:11:08Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2020-06-17T10:11:08Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2020-06-17T10:11:08Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2020-06-17T10:11:08Z DEBUG add: 'dc=lin,dc=test,dc=lan' to schema-compat-restrict-subtree, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value ['dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: updated value ['dc=lin,dc=test,dc=lan', 'cn=Schema Compatibility,cn=plugins,cn=config'] 2020-06-17T10:11:08Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan' to schema-compat-ignore-subtree, current value [] 2020-06-17T10:11:08Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan' to schema-compat-ignore-subtree, current value ['cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan', 'cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG groups 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=groups 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=groups, cn=accounts, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG objectclass=posixGroup 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG cn=%{cn} 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=posixGroup 2020-06-17T10:11:08Z DEBUG gidNumber=%{gidNumber} 2020-06-17T10:11:08Z DEBUG memberUid=%{memberUid} 2020-06-17T10:11:08Z DEBUG memberUid=%deref_r("member","uid") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","") 2020-06-17T10:11:08Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-17T10:11:08Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG schema-compat-restrict-subtree: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG schema-compat-ignore-subtree: 2020-06-17T10:11:08Z DEBUG cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG [(2, 'schema-compat-ignore-subtree', ['cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan', 'cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan']), (2, 'schema-compat-restrict-subtree', ['dc=lin,dc=test,dc=lan', 'cn=Schema Compatibility,cn=plugins,cn=config'])] 2020-06-17T10:11:08Z DEBUG Updated 1 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsSlapdPlugin 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG Schema Compatibility 2020-06-17T10:11:08Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:08Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2020-06-17T10:11:08Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:08Z DEBUG schema_compat_plugin_init 2020-06-17T10:11:08Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:08Z DEBUG object 2020-06-17T10:11:08Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:08Z DEBUG on 2020-06-17T10:11:08Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:08Z DEBUG schema-compat-plugin 2020-06-17T10:11:08Z DEBUG nsslapd-pluginprecedence: 2020-06-17T10:11:08Z DEBUG 40 2020-06-17T10:11:08Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:08Z DEBUG 0.8 2020-06-17T10:11:08Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:11:08Z DEBUG on 2020-06-17T10:11:08Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:08Z DEBUG redhat.com 2020-06-17T10:11:08Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:08Z DEBUG Schema Compatibility Plugin 2020-06-17T10:11:08Z DEBUG add: '40' to nsslapd-pluginprecedence, current value ['40'] 2020-06-17T10:11:08Z DEBUG add: updated value ['40'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG nsSlapdPlugin 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG Schema Compatibility 2020-06-17T10:11:08Z DEBUG nsslapd-pluginPath: 2020-06-17T10:11:08Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2020-06-17T10:11:08Z DEBUG nsslapd-pluginInitfunc: 2020-06-17T10:11:08Z DEBUG schema_compat_plugin_init 2020-06-17T10:11:08Z DEBUG nsslapd-pluginType: 2020-06-17T10:11:08Z DEBUG object 2020-06-17T10:11:08Z DEBUG nsslapd-pluginEnabled: 2020-06-17T10:11:08Z DEBUG on 2020-06-17T10:11:08Z DEBUG nsslapd-pluginId: 2020-06-17T10:11:08Z DEBUG schema-compat-plugin 2020-06-17T10:11:08Z DEBUG nsslapd-pluginprecedence: 2020-06-17T10:11:08Z DEBUG 40 2020-06-17T10:11:08Z DEBUG nsslapd-pluginVersion: 2020-06-17T10:11:08Z DEBUG 0.8 2020-06-17T10:11:08Z DEBUG nsslapd-pluginbetxn: 2020-06-17T10:11:08Z DEBUG on 2020-06-17T10:11:08Z DEBUG nsslapd-pluginVendor: 2020-06-17T10:11:08Z DEBUG redhat.com 2020-06-17T10:11:08Z DEBUG nsslapd-pluginDescription: 2020-06-17T10:11:08Z DEBUG Schema Compatibility Plugin 2020-06-17T10:11:08Z DEBUG [] 2020-06-17T10:11:08Z DEBUG Updated 0 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG users 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=users 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=users, cn=accounts, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG objectclass=posixAccount 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG uid=%{uid} 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=posixAccount 2020-06-17T10:11:08Z DEBUG gecos=%{cn} 2020-06-17T10:11:08Z DEBUG cn=%{cn} 2020-06-17T10:11:08Z DEBUG uidNumber=%{uidNumber} 2020-06-17T10:11:08Z DEBUG gidNumber=%{gidNumber} 2020-06-17T10:11:08Z DEBUG loginShell=%{loginShell} 2020-06-17T10:11:08Z DEBUG homeDirectory=%{homeDirectory} 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","") 2020-06-17T10:11:08Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-17T10:11:08Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG schema-compat-ignore-subtree: 2020-06-17T10:11:08Z DEBUG cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-restrict-subtree: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2020-06-17T10:11:08Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")' to schema-compat-entry-attribute, current value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")'] 2020-06-17T10:11:08Z DEBUG add: 'ipaanchoruuid=%{ipaanchoruuid}' to schema-compat-entry-attribute, current value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}'] 2020-06-17T10:11:08Z DEBUG add: '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG users 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=users 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=users, cn=accounts, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG objectclass=posixAccount 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG uid=%{uid} 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=posixAccount 2020-06-17T10:11:08Z DEBUG gecos=%{cn} 2020-06-17T10:11:08Z DEBUG cn=%{cn} 2020-06-17T10:11:08Z DEBUG uidNumber=%{uidNumber} 2020-06-17T10:11:08Z DEBUG gidNumber=%{gidNumber} 2020-06-17T10:11:08Z DEBUG loginShell=%{loginShell} 2020-06-17T10:11:08Z DEBUG homeDirectory=%{homeDirectory} 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","") 2020-06-17T10:11:08Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-17T10:11:08Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG schema-compat-ignore-subtree: 2020-06-17T10:11:08Z DEBUG cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-restrict-subtree: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG [] 2020-06-17T10:11:08Z DEBUG Updated 0 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG groups 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=groups 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=groups, cn=accounts, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG objectclass=posixGroup 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG cn=%{cn} 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=posixGroup 2020-06-17T10:11:08Z DEBUG gidNumber=%{gidNumber} 2020-06-17T10:11:08Z DEBUG memberUid=%{memberUid} 2020-06-17T10:11:08Z DEBUG memberUid=%deref_r("member","uid") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","") 2020-06-17T10:11:08Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-17T10:11:08Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG schema-compat-ignore-subtree: 2020-06-17T10:11:08Z DEBUG cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-restrict-subtree: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2020-06-17T10:11:08Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")'] 2020-06-17T10:11:08Z DEBUG add: 'ipaanchoruuid=%{ipaanchoruuid}' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}'] 2020-06-17T10:11:08Z DEBUG add: '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG groups 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=groups 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=groups, cn=accounts, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG objectclass=posixGroup 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG cn=%{cn} 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=posixGroup 2020-06-17T10:11:08Z DEBUG gidNumber=%{gidNumber} 2020-06-17T10:11:08Z DEBUG memberUid=%{memberUid} 2020-06-17T10:11:08Z DEBUG memberUid=%deref_r("member","uid") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","") 2020-06-17T10:11:08Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-17T10:11:08Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG schema-compat-ignore-subtree: 2020-06-17T10:11:08Z DEBUG cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-restrict-subtree: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG [] 2020-06-17T10:11:08Z DEBUG Updated 0 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG users 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=users 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=users, cn=accounts, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG objectclass=posixAccount 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG uid=%{uid} 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=posixAccount 2020-06-17T10:11:08Z DEBUG gecos=%{cn} 2020-06-17T10:11:08Z DEBUG cn=%{cn} 2020-06-17T10:11:08Z DEBUG uidNumber=%{uidNumber} 2020-06-17T10:11:08Z DEBUG gidNumber=%{gidNumber} 2020-06-17T10:11:08Z DEBUG loginShell=%{loginShell} 2020-06-17T10:11:08Z DEBUG homeDirectory=%{homeDirectory} 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","") 2020-06-17T10:11:08Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-17T10:11:08Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG schema-compat-ignore-subtree: 2020-06-17T10:11:08Z DEBUG cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-restrict-subtree: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG add: 'uid=%{uid}' to schema-compat-entry-attribute, current value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2020-06-17T10:11:08Z DEBUG add: updated value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', 'uid=%{uid}'] 2020-06-17T10:11:08Z DEBUG replace: updated value ['uid=%first("%{uid}")'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG users 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=users 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=users, cn=accounts, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG objectclass=posixAccount 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG uid=%first("%{uid}") 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=posixAccount 2020-06-17T10:11:08Z DEBUG gecos=%{cn} 2020-06-17T10:11:08Z DEBUG cn=%{cn} 2020-06-17T10:11:08Z DEBUG uidNumber=%{uidNumber} 2020-06-17T10:11:08Z DEBUG gidNumber=%{gidNumber} 2020-06-17T10:11:08Z DEBUG loginShell=%{loginShell} 2020-06-17T10:11:08Z DEBUG homeDirectory=%{homeDirectory} 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","") 2020-06-17T10:11:08Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-17T10:11:08Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG uid=%{uid} 2020-06-17T10:11:08Z DEBUG schema-compat-ignore-subtree: 2020-06-17T10:11:08Z DEBUG cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-restrict-subtree: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG [(1, 'schema-compat-entry-rdn', ['uid=%{uid}']), (0, 'schema-compat-entry-rdn', ['uid=%first("%{uid}")']), (0, 'schema-compat-entry-attribute', ['uid=%{uid}'])] 2020-06-17T10:11:08Z DEBUG Updated 1 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/80-schema_compat.update 0.214 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/81-externalmembers.update' 2020-06-17T10:11:08Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Initial value 2020-06-17T10:11:08Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG groups 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=groups 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=groups, cn=accounts, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG objectclass=posixGroup 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG cn=%{cn} 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=posixGroup 2020-06-17T10:11:08Z DEBUG gidNumber=%{gidNumber} 2020-06-17T10:11:08Z DEBUG memberUid=%{memberUid} 2020-06-17T10:11:08Z DEBUG memberUid=%deref_r("member","uid") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","") 2020-06-17T10:11:08Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-17T10:11:08Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG schema-compat-ignore-subtree: 2020-06-17T10:11:08Z DEBUG cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-restrict-subtree: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG addifexist: 'ipaexternalmember=%deref_r("member","ipaexternalmember")' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2020-06-17T10:11:08Z DEBUG addifexist: set schema-compat-entry-attribute to ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', 'ipaexternalmember=%deref_r("member","ipaexternalmember")'] 2020-06-17T10:11:08Z DEBUG addifexist: 'objectclass=ipaexternalgroup' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', 'ipaexternalmember=%deref_r("member","ipaexternalmember")'] 2020-06-17T10:11:08Z DEBUG addifexist: set schema-compat-entry-attribute to ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', 'ipaexternalmember=%deref_r("member","ipaexternalmember")', 'objectclass=ipaexternalgroup'] 2020-06-17T10:11:08Z DEBUG --------------------------------------------- 2020-06-17T10:11:08Z DEBUG Final value after applying updates 2020-06-17T10:11:08Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG objectClass: 2020-06-17T10:11:08Z DEBUG top 2020-06-17T10:11:08Z DEBUG extensibleObject 2020-06-17T10:11:08Z DEBUG cn: 2020-06-17T10:11:08Z DEBUG groups 2020-06-17T10:11:08Z DEBUG schema-compat-container-group: 2020-06-17T10:11:08Z DEBUG cn=compat, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-container-rdn: 2020-06-17T10:11:08Z DEBUG cn=groups 2020-06-17T10:11:08Z DEBUG schema-compat-search-base: 2020-06-17T10:11:08Z DEBUG cn=groups, cn=accounts, dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-search-filter: 2020-06-17T10:11:08Z DEBUG objectclass=posixGroup 2020-06-17T10:11:08Z DEBUG schema-compat-entry-rdn: 2020-06-17T10:11:08Z DEBUG cn=%{cn} 2020-06-17T10:11:08Z DEBUG schema-compat-entry-attribute: 2020-06-17T10:11:08Z DEBUG objectclass=posixGroup 2020-06-17T10:11:08Z DEBUG gidNumber=%{gidNumber} 2020-06-17T10:11:08Z DEBUG memberUid=%{memberUid} 2020-06-17T10:11:08Z DEBUG memberUid=%deref_r("member","uid") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:lin.test.lan:%{ipauniqueid}","") 2020-06-17T10:11:08Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-17T10:11:08Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-17T10:11:08Z DEBUG ipaexternalmember=%deref_r("member","ipaexternalmember") 2020-06-17T10:11:08Z DEBUG objectclass=ipaexternalgroup 2020-06-17T10:11:08Z DEBUG schema-compat-ignore-subtree: 2020-06-17T10:11:08Z DEBUG cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG schema-compat-restrict-subtree: 2020-06-17T10:11:08Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:08Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-17T10:11:08Z DEBUG [(0, 'schema-compat-entry-attribute', ['ipaexternalmember=%deref_r("member","ipaexternalmember")', 'objectclass=ipaexternalgroup'])] 2020-06-17T10:11:08Z DEBUG Updated 1 2020-06-17T10:11:08Z DEBUG Done 2020-06-17T10:11:08Z DEBUG LDAP update duration: /usr/share/ipa/updates/81-externalmembers.update 0.013 sec 2020-06-17T10:11:08Z DEBUG Parsing update file '/usr/share/ipa/updates/90-post_upgrade_plugins.update' 2020-06-17T10:11:08Z DEBUG Executing upgrade plugin: update_ca_topology 2020-06-17T10:11:08Z DEBUG raw: update_ca_topology 2020-06-17T10:11:08Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:08Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:11:08Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.aci 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.automember 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.automount 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-06-17T10:11:08Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.batch 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.ca 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.cert 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.config 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.dns 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.group 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-06-17T10:11:08Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.host 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.internal 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.join 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.location 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.migration 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.misc 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.otp 2020-06-17T10:11:08Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.permission 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.ping 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-06-17T10:11:08Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.role 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.schema 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.server 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.service 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.session 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-06-17T10:11:08Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.topology 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.trust 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.user 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.vault 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-06-17T10:11:08Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-06-17T10:11:08Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.install.plugins.dns 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2020-06-17T10:11:08Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2020-06-17T10:11:09Z DEBUG Created connection context.ldap2_139849939545168 2020-06-17T10:11:09Z DEBUG Destroyed connection context.ldap2_139849939545168 2020-06-17T10:11:09Z DEBUG Created connection context.ldap2_139849939545168 2020-06-17T10:11:09Z DEBUG Parsing update file '/usr/share/ipa/ca-topology.uldif' 2020-06-17T10:11:09Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:11:09Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:11:10Z DEBUG Updating existing entry: cn=freeipaserver.lin.test.lan,cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:10Z DEBUG --------------------------------------------- 2020-06-17T10:11:10Z DEBUG Initial value 2020-06-17T10:11:10Z DEBUG dn: cn=freeipaserver.lin.test.lan,cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:10Z DEBUG objectClass: 2020-06-17T10:11:10Z DEBUG top 2020-06-17T10:11:10Z DEBUG nsContainer 2020-06-17T10:11:10Z DEBUG ipaReplTopoManagedServer 2020-06-17T10:11:10Z DEBUG ipaConfigObject 2020-06-17T10:11:10Z DEBUG ipaSupportedDomainLevelConfig 2020-06-17T10:11:10Z DEBUG cn: 2020-06-17T10:11:10Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:11:10Z DEBUG ipaReplTopoManagedSuffix: 2020-06-17T10:11:10Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:10Z DEBUG ipaMinDomainLevel: 2020-06-17T10:11:10Z DEBUG 1 2020-06-17T10:11:10Z DEBUG ipaMaxDomainLevel: 2020-06-17T10:11:10Z DEBUG 1 2020-06-17T10:11:10Z DEBUG add: 'ipaReplTopoManagedServer' to objectclass, current value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig'] 2020-06-17T10:11:10Z DEBUG add: updated value ['top', 'nsContainer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig', 'ipaReplTopoManagedServer'] 2020-06-17T10:11:10Z DEBUG add: 'o=ipaca' to ipaReplTopoManagedSuffix, current value ['dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:10Z DEBUG add: updated value ['dc=lin,dc=test,dc=lan', 'o=ipaca'] 2020-06-17T10:11:10Z DEBUG --------------------------------------------- 2020-06-17T10:11:10Z DEBUG Final value after applying updates 2020-06-17T10:11:10Z DEBUG dn: cn=freeipaserver.lin.test.lan,cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:10Z DEBUG objectClass: 2020-06-17T10:11:10Z DEBUG top 2020-06-17T10:11:10Z DEBUG nsContainer 2020-06-17T10:11:10Z DEBUG ipaConfigObject 2020-06-17T10:11:10Z DEBUG ipaSupportedDomainLevelConfig 2020-06-17T10:11:10Z DEBUG ipaReplTopoManagedServer 2020-06-17T10:11:10Z DEBUG cn: 2020-06-17T10:11:10Z DEBUG freeipaserver.lin.test.lan 2020-06-17T10:11:10Z DEBUG ipaReplTopoManagedSuffix: 2020-06-17T10:11:10Z DEBUG dc=lin,dc=test,dc=lan 2020-06-17T10:11:10Z DEBUG o=ipaca 2020-06-17T10:11:10Z DEBUG ipaMinDomainLevel: 2020-06-17T10:11:10Z DEBUG 1 2020-06-17T10:11:10Z DEBUG ipaMaxDomainLevel: 2020-06-17T10:11:10Z DEBUG 1 2020-06-17T10:11:10Z DEBUG [(0, 'ipaReplTopoManagedSuffix', ['o=ipaca'])] 2020-06-17T10:11:10Z DEBUG Updated 1 2020-06-17T10:11:10Z DEBUG Done 2020-06-17T10:11:10Z DEBUG New entry: cn=ca,cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:10Z DEBUG --------------------------------------------- 2020-06-17T10:11:10Z DEBUG Initial value 2020-06-17T10:11:10Z DEBUG dn: cn=ca,cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:10Z DEBUG objectclass: 2020-06-17T10:11:10Z DEBUG top 2020-06-17T10:11:10Z DEBUG iparepltopoconf 2020-06-17T10:11:10Z DEBUG ipaReplTopoConfRoot: 2020-06-17T10:11:10Z DEBUG o=ipaca 2020-06-17T10:11:10Z DEBUG cn: 2020-06-17T10:11:10Z DEBUG ca 2020-06-17T10:11:10Z DEBUG --------------------------------------------- 2020-06-17T10:11:10Z DEBUG Final value after applying updates 2020-06-17T10:11:10Z DEBUG dn: cn=ca,cn=topology,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:10Z DEBUG objectclass: 2020-06-17T10:11:10Z DEBUG top 2020-06-17T10:11:10Z DEBUG iparepltopoconf 2020-06-17T10:11:10Z DEBUG ipaReplTopoConfRoot: 2020-06-17T10:11:10Z DEBUG o=ipaca 2020-06-17T10:11:10Z DEBUG cn: 2020-06-17T10:11:10Z DEBUG ca 2020-06-17T10:11:10Z DEBUG New entry: cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2020-06-17T10:11:10Z DEBUG --------------------------------------------- 2020-06-17T10:11:10Z DEBUG Initial value 2020-06-17T10:11:10Z DEBUG dn: cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2020-06-17T10:11:10Z DEBUG onlyifexist: 'cn=replication managers,cn=sysaccounts,cn=etc,dc=lin,dc=test,dc=lan' to nsds5replicabinddngroup, current value [] 2020-06-17T10:11:10Z DEBUG --------------------------------------------- 2020-06-17T10:11:10Z DEBUG Final value after applying updates 2020-06-17T10:11:10Z DEBUG dn: cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2020-06-17T10:11:10Z DEBUG LDAP update duration: /usr/share/ipa/ca-topology.uldif 0.177 sec 2020-06-17T10:11:10Z DEBUG Destroyed connection context.ldap2_139849939545168 2020-06-17T10:11:10Z DEBUG Executing upgrade plugin: update_ipaconfigstring_dnsversion_to_ipadnsversion 2020-06-17T10:11:10Z DEBUG raw: update_ipaconfigstring_dnsversion_to_ipadnsversion 2020-06-17T10:11:10Z DEBUG Executing upgrade plugin: update_dnszones 2020-06-17T10:11:10Z DEBUG raw: update_dnszones 2020-06-17T10:11:10Z DEBUG Executing upgrade plugin: update_dns_limits 2020-06-17T10:11:10Z DEBUG raw: update_dns_limits 2020-06-17T10:11:10Z DEBUG Executing upgrade plugin: update_sigden_extdom_broken_config 2020-06-17T10:11:10Z DEBUG raw: update_sigden_extdom_broken_config 2020-06-17T10:11:10Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:11:10Z DEBUG configured basedn for cn=IPA SIDGEN,cn=plugins,cn=config is okay 2020-06-17T10:11:10Z DEBUG configured basedn for cn=ipa_extdom_extop,cn=plugins,cn=config is okay 2020-06-17T10:11:10Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:11:10Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:11:10Z DEBUG Executing upgrade plugin: update_sids 2020-06-17T10:11:10Z DEBUG raw: update_sids 2020-06-17T10:11:10Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:11:10Z DEBUG SIDs do not need to be generated 2020-06-17T10:11:10Z DEBUG Executing upgrade plugin: update_default_range 2020-06-17T10:11:10Z DEBUG raw: update_default_range 2020-06-17T10:11:10Z DEBUG default_range: ipaDomainIDRange entry found, skip plugin 2020-06-17T10:11:10Z DEBUG Executing upgrade plugin: update_default_trust_view 2020-06-17T10:11:10Z DEBUG raw: update_default_trust_view 2020-06-17T10:11:10Z DEBUG raw: adtrust_is_enabled(version='2.235') 2020-06-17T10:11:10Z DEBUG adtrust_is_enabled(version='2.235') 2020-06-17T10:11:10Z DEBUG AD Trusts are not enabled on this server 2020-06-17T10:11:10Z DEBUG Executing upgrade plugin: update_tdo_gidnumber 2020-06-17T10:11:10Z DEBUG raw: update_tdo_gidnumber 2020-06-17T10:11:10Z DEBUG raw: adtrust_is_enabled(version='2.235') 2020-06-17T10:11:10Z DEBUG adtrust_is_enabled(version='2.235') 2020-06-17T10:11:10Z DEBUG AD Trusts are not enabled on this server 2020-06-17T10:11:10Z DEBUG Executing upgrade plugin: update_tdo_to_new_layout 2020-06-17T10:11:10Z DEBUG raw: update_tdo_to_new_layout 2020-06-17T10:11:10Z DEBUG raw: adtrust_is_enabled(version='2.235') 2020-06-17T10:11:10Z DEBUG adtrust_is_enabled(version='2.235') 2020-06-17T10:11:10Z DEBUG AD Trusts are not enabled on this server 2020-06-17T10:11:10Z DEBUG Executing upgrade plugin: update_host_cifs_keytabs 2020-06-17T10:11:10Z DEBUG raw: update_host_cifs_keytabs 2020-06-17T10:11:10Z DEBUG raw: adtrust_is_enabled(version='2.235') 2020-06-17T10:11:10Z DEBUG adtrust_is_enabled(version='2.235') 2020-06-17T10:11:10Z DEBUG AD Trusts are not enabled on this server 2020-06-17T10:11:10Z DEBUG Executing upgrade plugin: update_tdo_default_read_keys_permissions 2020-06-17T10:11:10Z DEBUG raw: update_tdo_default_read_keys_permissions 2020-06-17T10:11:10Z DEBUG raw: adtrust_is_enabled(version='2.235') 2020-06-17T10:11:10Z DEBUG adtrust_is_enabled(version='2.235') 2020-06-17T10:11:10Z DEBUG AD Trusts are not enabled on this server 2020-06-17T10:11:10Z DEBUG Executing upgrade plugin: update_adtrust_agents_members 2020-06-17T10:11:10Z DEBUG raw: update_adtrust_agents_members 2020-06-17T10:11:10Z DEBUG raw: adtrust_is_enabled(version='2.235') 2020-06-17T10:11:10Z DEBUG adtrust_is_enabled(version='2.235') 2020-06-17T10:11:10Z DEBUG AD Trusts are not enabled on this server 2020-06-17T10:11:10Z DEBUG Executing upgrade plugin: update_ca_renewal_master 2020-06-17T10:11:10Z DEBUG raw: update_ca_renewal_master 2020-06-17T10:11:10Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:10Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:11:10Z DEBUG found CA renewal master freeipaserver.lin.test.lan 2020-06-17T10:11:10Z DEBUG Executing upgrade plugin: update_idrange_type 2020-06-17T10:11:10Z DEBUG raw: update_idrange_type 2020-06-17T10:11:10Z DEBUG update_idrange_type: search for ID ranges with no type set 2020-06-17T10:11:10Z DEBUG update_idrange_type: no ID range without type set found 2020-06-17T10:11:10Z DEBUG Executing upgrade plugin: update_pacs 2020-06-17T10:11:10Z DEBUG raw: update_pacs 2020-06-17T10:11:10Z DEBUG Adding nfs:NONE to default PAC types 2020-06-17T10:11:10Z DEBUG Executing upgrade plugin: update_service_principalalias 2020-06-17T10:11:10Z DEBUG raw: update_service_principalalias 2020-06-17T10:11:10Z DEBUG update_service_principalalias: search for affected services 2020-06-17T10:11:10Z DEBUG update_service_principalalias: found 2 services to update, truncated: False 2020-06-17T10:11:10Z DEBUG update_service_principalalias: all affected services updated 2020-06-17T10:11:10Z DEBUG Executing upgrade plugin: update_fix_duplicate_cacrt_in_ldap 2020-06-17T10:11:10Z DEBUG raw: update_fix_duplicate_cacrt_in_ldap 2020-06-17T10:11:10Z DEBUG raw: ca_is_enabled(version='2.235') 2020-06-17T10:11:10Z DEBUG ca_is_enabled(version='2.235') 2020-06-17T10:11:10Z DEBUG Found 1 entrie(s) for IPA CA in LDAP 2020-06-17T10:11:10Z DEBUG Destroyed connection context.ldap2_139849980197240 2020-06-17T10:11:10Z DEBUG Restarting directory server to apply updates 2020-06-17T10:11:10Z DEBUG Destroyed connection context.ldap2_139850008098072 2020-06-17T10:11:10Z DEBUG Starting external process 2020-06-17T10:11:10Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:11:13Z DEBUG Process finished, return code=0 2020-06-17T10:11:13Z DEBUG stdout= 2020-06-17T10:11:13Z DEBUG stderr= 2020-06-17T10:11:13Z DEBUG Restart of dirsrv@LIN-TEST-LAN.service complete 2020-06-17T10:11:13Z DEBUG Created connection context.ldap2_139850008098072 2020-06-17T10:11:13Z DEBUG Created connection context.ldap2_139849980197240 2020-06-17T10:11:13Z DEBUG Executing upgrade plugin: update_upload_cacrt 2020-06-17T10:11:13Z DEBUG raw: update_upload_cacrt 2020-06-17T10:11:13Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:11:13Z DEBUG raw: ca_is_enabled(version='2.235') 2020-06-17T10:11:13Z DEBUG ca_is_enabled(version='2.235') 2020-06-17T10:11:13Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:11:13Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:11:13Z DEBUG Starting external process 2020-06-17T10:11:13Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-LIN-TEST-LAN/', '-L', '-f', '/etc/dirsrv/slapd-LIN-TEST-LAN/pwdfile.txt'] 2020-06-17T10:11:13Z DEBUG Process finished, return code=0 2020-06-17T10:11:13Z DEBUG stdout= Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI LIN.TEST.LAN IPA CA CT,C,C Server-Cert u,u,u 2020-06-17T10:11:13Z DEBUG stderr= 2020-06-17T10:11:13Z DEBUG Starting external process 2020-06-17T10:11:13Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-LIN-TEST-LAN/', '-L', '-n', 'LIN.TEST.LAN IPA CA', '-a', '-f', '/etc/dirsrv/slapd-LIN-TEST-LAN/pwdfile.txt'] 2020-06-17T10:11:13Z DEBUG Process finished, return code=0 2020-06-17T10:11:13Z DEBUG stdout=-----BEGIN CERTIFICATE----- MIIEjjCCAvagAwIBAgIBATANBgkqhkiG9w0BAQsFADA3MRUwEwYDVQQKDAxMSU4u VEVTVC5MQU4xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMDA2 MTcxMDA3MjFaFw00MDA2MTcxMDA3MjFaMDcxFTATBgNVBAoMDExJTi5URVNULkxB TjEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MIIBojANBgkqhkiG9w0B AQEFAAOCAY8AMIIBigKCAYEAraJmeLv5JRkWpW+M3y1Yd/BD6atlDnUUrTIUo7rC pGLrBs0Bu1aJWmeMj+tkp5iuC+ah93p9ABctuKAh9s56M4TQlcFcevrzCgE8FClM 5LpK2DkQNuNusopgxqUi/dYKXbdwGO64DqnQiJ5Z8hh1vvc2eeAIkAWThPuxH6UO dbESHS5m55aPhUK17OdvK6ukQxCMbplVH77SRZ0U3lpHzSbXrjKFwlRyEuq1IGAS hrhteZpFtxWl1BmfHmrNcNWUEAfHrhK1vKDBKzV2+u2lnKdASQlX2oPGg1H8Yxoe UO8Rm4eNqlnACv29SL2CHXAVcs1iTNCbTXkIndMhhhdPX/plv4l0JDyHJGwAmQXy K1O4i5OqNLeDt63z7llpxinpN0fev1qQ4q7LFy7+psJ01aP7/AuH/LxAChPnABlY G2Fs307O9lSYhpOrk49U/i/8Xadrc2LoTx8Cbj3kSnA8/FeSR/bVEORwMuYws71c 7dLDbsZUACu0uDsLSx1vikeTAgMBAAGjgaQwgaEwHwYDVR0jBBgwFoAUUTc1IALN KBOxVvPFwyWFIF8HeR4wDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAcYw HQYDVR0OBBYEFFE3NSACzSgTsVbzxcMlhSBfB3keMD4GCCsGAQUFBwEBBDIwMDAu BggrBgEFBQcwAYYiaHR0cDovL2lwYS1jYS5saW4udGVzdC5sYW4vY2Evb2NzcDAN BgkqhkiG9w0BAQsFAAOCAYEAfRexfx4eGi6qS9okGfK/M2PQ++JIj5som4aocW26 HsZcrbT5t/Vo9IYRhTDvq1nkNlHwl8OiiAi0rgJP6TOPbpp3V8mQcRgdXAA06hlb b5TX2KmSMC11rleR7NjeKxyMlTW9YpyBU5WrjL28MMEt9tL6O4lMivA3dXEX2D4u l+7MOURdHx8Gxsz3Sv1AOoZwmL/evGTkURrf1ArfrH3G/IguFKUTSI939s/baIyY MBp6z1VagQeeoCHI7gw5flT5oezeoLp620I4vJ7YH22rrfkHLxL8WZ4NpRqcgKfO fDKVHT28meSAdVajABznAsOq1uYK5yQWhoK8ug9gNCUjrjukh2bb3lOwDVuz7fLS Sr02x6ghisReo7uP0EZ4CajvyhPcVn+rcpL+x/SKd1vK9iN91THTDtC7eYwYNGpG vqMnn7mt+rACtBGneE+/rtmL8YedIyIhrSBtPpDnR4ptglRMyRTs7Fnor0fJ8dDV L0MoRipLMGUN5SDzZ5foD9OU -----END CERTIFICATE----- 2020-06-17T10:11:13Z DEBUG stderr= 2020-06-17T10:11:13Z DEBUG Executing upgrade plugin: update_ra_cert_store 2020-06-17T10:11:13Z DEBUG raw: update_ra_cert_store 2020-06-17T10:11:13Z DEBUG raw: ca_is_enabled(version='2.235') 2020-06-17T10:11:13Z DEBUG ca_is_enabled(version='2.235') 2020-06-17T10:11:13Z DEBUG Executing upgrade plugin: update_mapping_Guests_to_nobody 2020-06-17T10:11:13Z DEBUG raw: update_mapping_Guests_to_nobody 2020-06-17T10:11:13Z DEBUG raw: adtrust_is_enabled(version='2.235') 2020-06-17T10:11:13Z DEBUG adtrust_is_enabled(version='2.235') 2020-06-17T10:11:13Z DEBUG AD Trusts are not enabled on this server 2020-06-17T10:11:13Z DEBUG Executing upgrade plugin: fix_kra_people_entry 2020-06-17T10:11:13Z DEBUG raw: fix_kra_people_entry 2020-06-17T10:11:13Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:13Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:11:13Z DEBUG Executing upgrade plugin: update_master_to_dnsforwardzones 2020-06-17T10:11:13Z DEBUG raw: update_master_to_dnsforwardzones 2020-06-17T10:11:13Z DEBUG raw: dnsconfig_show(all=True, version='2.235') 2020-06-17T10:11:13Z DEBUG dnsconfig_show(rights=False, all=True, raw=False, version='2.235') 2020-06-17T10:11:13Z DEBUG Executing upgrade plugin: update_dnsforward_emptyzones 2020-06-17T10:11:13Z DEBUG raw: update_dnsforward_emptyzones 2020-06-17T10:11:13Z DEBUG raw: dnsconfig_show(all=True, version='2.235') 2020-06-17T10:11:13Z DEBUG dnsconfig_show(rights=False, all=True, raw=False, version='2.235') 2020-06-17T10:11:13Z DEBUG Executing upgrade plugin: update_managed_post 2020-06-17T10:11:13Z DEBUG raw: update_managed_post 2020-06-17T10:11:13Z DEBUG Executing upgrade plugin: update_managed_permissions 2020-06-17T10:11:13Z DEBUG raw: update_managed_permissions 2020-06-17T10:11:13Z DEBUG Anonymous ACI not found 2020-06-17T10:11:13Z DEBUG Updating managed permissions for automember 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Read Automember Definitions 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Read Automember Definitions 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "automemberdefaultgroup || automemberdisabled || automemberfilter || automembergroupingattr || automemberscope || cn || createtimestamp || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=automemberdefinition)")(version 3.0;acl "permission:System: Read Automember Definitions";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Definitions,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=automember,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Read Automember Rules 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Read Automember Rules 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "automemberexclusiveregex || automemberinclusiveregex || automembertargetgroup || cn || createtimestamp || description || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=automemberregexrule)")(version 3.0;acl "permission:System: Read Automember Rules";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Rules,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=automember,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Read Automember Tasks 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Read Automember Tasks 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "*")(target = "ldap:///cn=*,cn=automember rebuild membership,cn=tasks,cn=config")(version 3.0;acl "permission:System: Read Automember Tasks";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Tasks,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=tasks,cn=config 2020-06-17T10:11:13Z DEBUG Updating managed permissions for automountkey 2020-06-17T10:11:13Z DEBUG Legacy permission Add Automount keys not found 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Add Automount Keys 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Add Automount Keys 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetfilter = "(objectclass=automount)")(version 3.0;acl "permission:System: Add Automount Keys";allow (add) groupdn = "ldap:///cn=System: Add Automount Keys,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=automount,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Legacy permission Modify Automount keys not found 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Modify Automount Keys 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Modify Automount Keys 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "automountinformation || automountkey || description")(targetfilter = "(objectclass=automount)")(version 3.0;acl "permission:System: Modify Automount Keys";allow (write) groupdn = "ldap:///cn=System: Modify Automount Keys,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=automount,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Legacy permission Remove Automount keys not found 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Remove Automount Keys 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Remove Automount Keys 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetfilter = "(objectclass=automount)")(version 3.0;acl "permission:System: Remove Automount Keys";allow (delete) groupdn = "ldap:///cn=System: Remove Automount Keys,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=automount,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permissions for automountlocation 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Add Automount Locations 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Add Automount Locations 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Add Automount Locations";allow (add) groupdn = "ldap:///cn=System: Add Automount Locations,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=automount,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Read Automount Configuration 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Read Automount Configuration 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "automountinformation || automountkey || automountmapname || cn || createtimestamp || description || entryusn || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Automount Configuration";allow (compare,read,search) userdn = "ldap:///anyone";)' to cn=automount,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Remove Automount Locations 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Remove Automount Locations 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Remove Automount Locations";allow (delete) groupdn = "ldap:///cn=System: Remove Automount Locations,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=automount,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permissions for automountmap 2020-06-17T10:11:13Z DEBUG Legacy permission Add Automount maps not found 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Add Automount Maps 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Add Automount Maps 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetfilter = "(objectclass=automountmap)")(version 3.0;acl "permission:System: Add Automount Maps";allow (add) groupdn = "ldap:///cn=System: Add Automount Maps,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=automount,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Legacy permission Modify Automount maps not found 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Modify Automount Maps 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Modify Automount Maps 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "automountmapname || description")(targetfilter = "(objectclass=automountmap)")(version 3.0;acl "permission:System: Modify Automount Maps";allow (write) groupdn = "ldap:///cn=System: Modify Automount Maps,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=automount,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Legacy permission Remove Automount maps not found 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Remove Automount Maps 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Remove Automount Maps 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetfilter = "(objectclass=automountmap)")(version 3.0;acl "permission:System: Remove Automount Maps";allow (delete) groupdn = "ldap:///cn=System: Remove Automount Maps,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=automount,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permissions for ca 2020-06-17T10:11:13Z DEBUG Legacy permission Add CA not found 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Add CA 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Add CA 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Add CA";allow (add) groupdn = "ldap:///cn=System: Add CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=cas,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Legacy permission Delete CA not found 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Delete CA 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Delete CA 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Delete CA";allow (delete) groupdn = "ldap:///cn=System: Delete CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=cas,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Legacy permission Modify CA not found 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Modify CA 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Modify CA 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "cn || description")(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Modify CA";allow (write) groupdn = "ldap:///cn=System: Modify CA,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=cas,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Read CAs 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Read CAs 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || ipacaid || ipacaissuerdn || ipacasubjectdn || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Read CAs";allow (compare,read,search) userdn = "ldap:///all";)' to cn=cas,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permissions for caacl 2020-06-17T10:11:13Z DEBUG Legacy permission Add CA ACL not found 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Add CA ACL 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Add CA ACL 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Add CA ACL";allow (add) groupdn = "ldap:///cn=System: Add CA ACL,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=caacls,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Legacy permission Delete CA ACL not found 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Delete CA ACL 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Delete CA ACL 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Delete CA ACL";allow (delete) groupdn = "ldap:///cn=System: Delete CA ACL,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=caacls,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Legacy permission Manage CA ACL membership not found 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Manage CA ACL Membership 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Manage CA ACL Membership 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "hostcategory || ipacacategory || ipacertprofilecategory || ipamemberca || ipamembercertprofile || memberhost || memberservice || memberuser || servicecategory || usercategory")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Manage CA ACL Membership";allow (write) groupdn = "ldap:///cn=System: Manage CA ACL Membership,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=caacls,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Legacy permission Modify CA ACL not found 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Modify CA ACL 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Modify CA ACL 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "cn || description || ipaenabledflag")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Modify CA ACL";allow (write) groupdn = "ldap:///cn=System: Modify CA ACL,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=caacls,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Read CA ACLs 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Read CA ACLs 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || hostcategory || ipacacategory || ipacertprofilecategory || ipaenabledflag || ipamemberca || ipamembercertprofile || ipauniqueid || member || memberhost || memberservice || memberuser || modifytimestamp || objectclass || servicecategory || usercategory")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Read CA ACLs";allow (compare,read,search) userdn = "ldap:///all";)' to cn=caacls,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permissions for certmapconfig 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Modify Certmap Configuration 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Modify Certmap Configuration 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "ipacertmappromptusername")(targetfilter = "(objectclass=ipacertmapconfigobject)")(version 3.0;acl "permission:System: Modify Certmap Configuration";allow (write) groupdn = "ldap:///cn=System: Modify Certmap Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=certmap,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Read Certmap Configuration 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Read Certmap Configuration 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "cn || ipacertmappromptusername")(targetfilter = "(objectclass=ipacertmapconfigobject)")(version 3.0;acl "permission:System: Read Certmap Configuration";allow (compare,read,search) userdn = "ldap:///all";)' to cn=certmap,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permissions for certmaprule 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Add Certmap Rules 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Add Certmap Rules 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Add Certmap Rules";allow (add) groupdn = "ldap:///cn=System: Add Certmap Rules,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=certmaprules,cn=certmap,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Delete Certmap Rules 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Delete Certmap Rules 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Delete Certmap Rules";allow (delete) groupdn = "ldap:///cn=System: Delete Certmap Rules,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=certmaprules,cn=certmap,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Modify Certmap Rules 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Modify Certmap Rules 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "associateddomain || cn || description || ipacertmapmaprule || ipacertmapmatchrule || ipacertmappriority || ipaenabledflag || objectclass")(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Modify Certmap Rules";allow (write) groupdn = "ldap:///cn=System: Modify Certmap Rules,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=certmaprules,cn=certmap,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Read Certmap Rules 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Read Certmap Rules 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "associateddomain || cn || createtimestamp || description || entryusn || ipacertmapmaprule || ipacertmapmatchrule || ipacertmappriority || ipaenabledflag || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Read Certmap Rules";allow (compare,read,search) userdn = "ldap:///all";)' to cn=certmaprules,cn=certmap,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permissions for certprofile 2020-06-17T10:11:13Z DEBUG Legacy permission Delete Certificate Profile not found 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Delete Certificate Profile 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Delete Certificate Profile 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Delete Certificate Profile";allow (delete) groupdn = "ldap:///cn=System: Delete Certificate Profile,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=certprofiles,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Legacy permission Import Certificate Profile not found 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Import Certificate Profile 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Import Certificate Profile 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Import Certificate Profile";allow (add) groupdn = "ldap:///cn=System: Import Certificate Profile,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=certprofiles,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Legacy permission Modify Certificate Profile not found 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Modify Certificate Profile 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Modify Certificate Profile 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "cn || description || ipacertprofilestoreissued")(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Modify Certificate Profile";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Profile,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=certprofiles,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Read Certificate Profiles 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Read Certificate Profiles 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || ipacertprofilestoreissued || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Read Certificate Profiles";allow (compare,read,search) userdn = "ldap:///all";)' to cn=certprofiles,cn=ca,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permissions for config 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Read Global Configuration 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Read Global Configuration 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || ipacertificatesubjectbase || ipaconfigstring || ipacustomfields || ipadefaultemaildomain || ipadefaultloginshell || ipadefaultprimarygroup || ipadomainresolutionorder || ipagroupobjectclasses || ipagroupsearchfields || ipahomesrootdir || ipakrbauthzdata || ipamaxhostnamelength || ipamaxusernamelength || ipamigrationenabled || ipapwdexpadvnotify || ipasearchrecordslimit || ipasearchtimelimit || ipaselinuxusermapdefault || ipaselinuxusermaporder || ipauserauthtype || ipauserobjectclasses || ipausersearchfields || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaguiconfig)")(version 3.0;acl "permission:System: Read Global Configuration";allow (compare,read,search) userdn = "ldap:///all";)' to cn=ipaConfig,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permissions for cosentry 2020-06-17T10:11:13Z DEBUG Legacy permission Add Group Password Policy costemplate not found 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Add Group Password Policy costemplate 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Add Group Password Policy costemplate 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetfilter = "(objectclass=costemplate)")(version 3.0;acl "permission:System: Add Group Password Policy costemplate";allow (add) groupdn = "ldap:///cn=System: Add Group Password Policy costemplate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=cosTemplates,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Legacy permission Delete Group Password Policy costemplate not found 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Delete Group Password Policy costemplate 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Delete Group Password Policy costemplate 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetfilter = "(objectclass=costemplate)")(version 3.0;acl "permission:System: Delete Group Password Policy costemplate";allow (delete) groupdn = "ldap:///cn=System: Delete Group Password Policy costemplate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=cosTemplates,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Legacy permission Modify Group Password Policy costemplate not found 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Modify Group Password Policy costemplate 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Modify Group Password Policy costemplate 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "cospriority")(targetfilter = "(objectclass=costemplate)")(version 3.0;acl "permission:System: Modify Group Password Policy costemplate";allow (write) groupdn = "ldap:///cn=System: Modify Group Password Policy costemplate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=cosTemplates,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Read Group Password Policy costemplate 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Read Group Password Policy costemplate 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "cn || cospriority || createtimestamp || entryusn || krbpwdpolicyreference || modifytimestamp || objectclass")(targetfilter = "(objectclass=costemplate)")(version 3.0;acl "permission:System: Read Group Password Policy costemplate";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Group Password Policy costemplate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=cosTemplates,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permissions for dnsconfig 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Read DNS Configuration 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Read DNS Configuration 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Legacy permission Write DNS Configuration not found 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Write DNS Configuration 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Write DNS Configuration 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:13Z DEBUG Updating managed permissions for dnsserver 2020-06-17T10:11:13Z DEBUG Updating managed permission: System: Modify DNS Servers Configuration 2020-06-17T10:11:13Z DEBUG Updating ACI for managed permission: System: Modify DNS Servers Configuration 2020-06-17T10:11:13Z DEBUG Adding ACI '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Read DNS Servers Configuration 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Read DNS Servers Configuration 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permissions for dnszone 2020-06-17T10:11:14Z DEBUG Legacy permission add dns entries not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Add DNS Entries 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Add DNS Entries 2020-06-17T10:11:14Z DEBUG Adding ACI '(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Manage DNSSEC keys 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Manage DNSSEC keys 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Manage DNSSEC metadata 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Manage DNSSEC metadata 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Read DNS Entries 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Read DNS Entries 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Legacy permission 'Read DNS Entries' not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Read DNSSEC metadata 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Read DNSSEC metadata 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Legacy permission remove dns entries not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Remove DNS Entries 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Remove DNS Entries 2020-06-17T10:11:14Z DEBUG Adding ACI '(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Legacy permission update dns entries not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Update DNS Entries 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Update DNS Entries 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permissions for group 2020-06-17T10:11:14Z DEBUG Legacy permission Add Groups not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Add Groups 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Add Groups 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Add Groups";allow (add) groupdn = "ldap:///cn=System: Add Groups,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Modify External Group Membership 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Modify External Group Membership 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "ipaexternalmember")(targetfilter = "(objectclass=ipaexternalgroup)")(version 3.0;acl "permission:System: Modify External Group Membership";allow (write) groupdn = "ldap:///cn=System: Modify External Group Membership,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Legacy permission Modify Group membership not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Modify Group Membership 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Modify Group Membership 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "member")(targetfilter = "(&(!(cn=admins))(objectclass=ipausergroup))")(version 3.0;acl "permission:System: Modify Group Membership";allow (write) groupdn = "ldap:///cn=System: Modify Group Membership,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Legacy permission Modify Groups not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Modify Groups 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Modify Groups 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "cn || description || gidnumber || ipauniqueid || membermanager || mepmanagedby || objectclass")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Modify Groups";allow (write) groupdn = "ldap:///cn=System: Modify Groups,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Read External Group Membership 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Read External Group Membership 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "ipaexternalmember")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read External Group Membership";allow (compare,read,search) userdn = "ldap:///all";)' to cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Read Group Compat Tree 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Read Group Compat Tree 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=lin,dc=test,dc=lan")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Read Group Membership 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Read Group Membership 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "member || memberhost || memberof || memberuid || memberuser")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read Group Membership";allow (compare,read,search) userdn = "ldap:///all";)' to cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Read Group Views Compat Tree 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Read Group Views Compat Tree 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=lin,dc=test,dc=lan")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Read Groups 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Read Groups 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || gidnumber || ipaexternalmember || ipantsecurityidentifier || ipauniqueid || membermanager || mepmanagedby || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read Groups";allow (compare,read,search) userdn = "ldap:///anyone";)' to cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Legacy permission Remove Groups not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Remove Groups 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Remove Groups 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Remove Groups";allow (delete) groupdn = "ldap:///cn=System: Remove Groups,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permissions for hbacrule 2020-06-17T10:11:14Z DEBUG Legacy permission Add HBAC rule not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Add HBAC Rule 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Add HBAC Rule 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Add HBAC Rule";allow (add) groupdn = "ldap:///cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Legacy permission Delete HBAC rule not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Delete HBAC Rule 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Delete HBAC Rule 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Delete HBAC Rule";allow (delete) groupdn = "ldap:///cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Legacy permission Manage HBAC rule membership not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Manage HBAC Rule Membership 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Manage HBAC Rule Membership 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "externalhost || memberhost || memberservice || memberuser")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Manage HBAC Rule Membership";allow (write) groupdn = "ldap:///cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Legacy permission Modify HBAC rule not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Modify HBAC Rule 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Modify HBAC Rule 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "accessruletype || accesstime || cn || description || hostcategory || ipaenabledflag || servicecategory || sourcehost || sourcehostcategory || usercategory")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Modify HBAC Rule";allow (write) groupdn = "ldap:///cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Read HBAC Rules 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Read HBAC Rules 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "accessruletype || accesstime || cn || createtimestamp || description || entryusn || externalhost || hostcategory || ipaenabledflag || ipauniqueid || member || memberhost || memberservice || memberuser || modifytimestamp || objectclass || servicecategory || sourcehost || sourcehostcategory || usercategory")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Read HBAC Rules";allow (compare,read,search) userdn = "ldap:///all";)' to cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permissions for hbacsvc 2020-06-17T10:11:14Z DEBUG Legacy permission Add HBAC services not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Add HBAC Services 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Add HBAC Services 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipahbacservice)")(version 3.0;acl "permission:System: Add HBAC Services";allow (add) groupdn = "ldap:///cn=System: Add HBAC Services,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Legacy permission Delete HBAC services not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Delete HBAC Services 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Delete HBAC Services 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipahbacservice)")(version 3.0;acl "permission:System: Delete HBAC Services";allow (delete) groupdn = "ldap:///cn=System: Delete HBAC Services,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Read HBAC Services 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Read HBAC Services 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || ipauniqueid || memberof || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahbacservice)")(version 3.0;acl "permission:System: Read HBAC Services";allow (compare,read,search) userdn = "ldap:///all";)' to cn=hbacservices,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permissions for hbacsvcgroup 2020-06-17T10:11:14Z DEBUG Legacy permission Add HBAC service groups not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Add HBAC Service Groups 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Add HBAC Service Groups 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipahbacservicegroup)")(version 3.0;acl "permission:System: Add HBAC Service Groups";allow (add) groupdn = "ldap:///cn=System: Add HBAC Service Groups,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=hbacservicegroups,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Legacy permission Delete HBAC service groups not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Delete HBAC Service Groups 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Delete HBAC Service Groups 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipahbacservicegroup)")(version 3.0;acl "permission:System: Delete HBAC Service Groups";allow (delete) groupdn = "ldap:///cn=System: Delete HBAC Service Groups,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=hbacservicegroups,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Legacy permission Manage HBAC service group membership not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Manage HBAC Service Group Membership 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Manage HBAC Service Group Membership 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "member")(targetfilter = "(objectclass=ipahbacservicegroup)")(version 3.0;acl "permission:System: Manage HBAC Service Group Membership";allow (write) groupdn = "ldap:///cn=System: Manage HBAC Service Group Membership,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=hbacservicegroups,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Read HBAC Service Groups 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Read HBAC Service Groups 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || ipauniqueid || member || memberhost || memberuser || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=ipahbacservicegroup)")(version 3.0;acl "permission:System: Read HBAC Service Groups";allow (compare,read,search) userdn = "ldap:///all";)' to cn=hbacservicegroups,cn=hbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permissions for host 2020-06-17T10:11:14Z DEBUG Legacy permission Add Hosts not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Add Hosts 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Add Hosts 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Add Hosts";allow (add) groupdn = "ldap:///cn=System: Add Hosts,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Legacy permission Add krbPrincipalName to a host not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Add krbPrincipalName to a Host 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Add krbPrincipalName to a Host 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "krbprincipalname")(targetfilter = "(&(!(krbprincipalname=*))(objectclass=ipahost))")(version 3.0;acl "permission:System: Add krbPrincipalName to a Host";allow (write) groupdn = "ldap:///cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Legacy permission Enroll a host not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Enroll a Host 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Enroll a Host 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "enrolledby || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Enroll a Host";allow (write) groupdn = "ldap:///cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Manage Host Certificates 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Manage Host Certificates 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "usercertificate")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Certificates";allow (write) groupdn = "ldap:///cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Manage Host Enrollment Password 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Manage Host Enrollment Password 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "userpassword")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Enrollment Password";allow (write) groupdn = "ldap:///cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Legacy permission Manage host keytab not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Manage Host Keytab 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Manage Host Keytab 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(&(!(memberOf=cn=ipaservers,cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan))(objectclass=ipahost))")(version 3.0;acl "permission:System: Manage Host Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Manage Host Keytab Permissions 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Manage Host Keytab Permissions 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Manage Host Principals 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Manage Host Principals 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Principals";allow (write) groupdn = "ldap:///cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Legacy permission Manage Host SSH Public Keys not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Manage Host SSH Public Keys 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Manage Host SSH Public Keys 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "ipasshpubkey")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Legacy permission Modify Hosts not found 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Modify Hosts 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Modify Hosts 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "description || ipaassignedidview || krbprincipalauthind || l || macaddress || nshardwareplatform || nshostlocation || nsosversion || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Modify Hosts";allow (write) groupdn = "ldap:///cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Read Host Compat Tree 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Read Host Compat Tree 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=lin,dc=test,dc=lan")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Read Host Membership 2020-06-17T10:11:14Z DEBUG Updating ACI for managed permission: System: Read Host Membership 2020-06-17T10:11:14Z DEBUG Adding ACI '(targetattr = "memberof")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Host Membership";allow (compare,read,search) userdn = "ldap:///all";)' to cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:14Z DEBUG Updating managed permission: System: Read Hosts 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read Hosts 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || enrolledby || entryusn || fqdn || ipaassignedidview || ipaclientversion || ipakrbauthzdata || ipasshpubkey || ipauniqueid || krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || l || macaddress || managedby || modifytimestamp || nshardwareplatform || nshostlocation || nsosversion || objectclass || serverhostname || usercertificate || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Hosts";allow (compare,read,search) userdn = "ldap:///all";)' to cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Legacy permission Remove Hosts not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Remove Hosts 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Remove Hosts 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Remove Hosts";allow (delete) groupdn = "ldap:///cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=computers,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permissions for hostgroup 2020-06-17T10:11:15Z DEBUG Legacy permission Add Hostgroups not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Add Hostgroups 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Add Hostgroups 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Add Hostgroups";allow (add) groupdn = "ldap:///cn=System: Add Hostgroups,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Legacy permission Modify Hostgroup membership not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Modify Hostgroup Membership 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Modify Hostgroup Membership 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "member")(targetfilter = "(&(!(cn=ipaservers))(objectclass=ipahostgroup))")(version 3.0;acl "permission:System: Modify Hostgroup Membership";allow (write) groupdn = "ldap:///cn=System: Modify Hostgroup Membership,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Legacy permission Modify Hostgroups not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Modify Hostgroups 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Modify Hostgroups 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "cn || description || membermanager")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Modify Hostgroups";allow (write) groupdn = "ldap:///cn=System: Modify Hostgroups,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read Hostgroup Membership 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read Hostgroup Membership 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "member || memberhost || memberof || memberuser")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Read Hostgroup Membership";allow (compare,read,search) userdn = "ldap:///all";)' to cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read Hostgroups 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read Hostgroups 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || ipauniqueid || membermanager || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Read Hostgroups";allow (compare,read,search) userdn = "ldap:///all";)' to cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Legacy permission Remove Hostgroups not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Remove Hostgroups 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Remove Hostgroups 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Remove Hostgroups";allow (delete) groupdn = "ldap:///cn=System: Remove Hostgroups,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=hostgroups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permissions for idoverridegroup 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read Group ID Overrides 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read Group ID Overrides 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || gidnumber || ipaanchoruuid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaGroupOverride)")(version 3.0;acl "permission:System: Read Group ID Overrides";allow (compare,read,search) userdn = "ldap:///all";)' to cn=views,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permissions for idoverrideuser 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read User ID Overrides 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read User ID Overrides 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "createtimestamp || description || entryusn || gecos || gidnumber || homedirectory || ipaanchoruuid || ipaoriginaluid || ipasshpubkey || loginshell || modifytimestamp || objectclass || uid || uidnumber || usercertificate")(targetfilter = "(objectclass=ipaUserOverride)")(version 3.0;acl "permission:System: Read User ID Overrides";allow (compare,read,search) userdn = "ldap:///all";)' to cn=views,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permissions for idrange 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read ID Ranges 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read ID Ranges 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || ipabaseid || ipabaserid || ipaidrangesize || ipanttrusteddomainsid || iparangetype || ipasecondarybaserid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidrange)")(version 3.0;acl "permission:System: Read ID Ranges";allow (compare,read,search) userdn = "ldap:///all";)' to cn=ranges,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permissions for idview 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read ID Views 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read ID Views 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || ipadomainresolutionorder || modifytimestamp || objectclass")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Read ID Views";allow (compare,read,search) userdn = "ldap:///all";)' to cn=views,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permissions for krbtpolicy 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read Default Kerberos Ticket Policy 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read Default Kerberos Ticket Policy 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "createtimestamp || entryusn || krbauthindmaxrenewableage || krbauthindmaxticketlife || krbdefaultencsalttypes || krbmaxrenewableage || krbmaxticketlife || krbsupportedencsalttypes || modifytimestamp || objectclass")(targetfilter = "(objectclass=krbticketpolicyaux)")(version 3.0;acl "permission:System: Read Default Kerberos Ticket Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Default Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read User Kerberos Ticket Policy 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read User Kerberos Ticket Policy 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "krbauthindmaxrenewableage || krbauthindmaxticketlife || krbmaxrenewableage || krbmaxticketlife")(targetfilter = "(objectclass=krbticketpolicyaux)")(version 3.0;acl "permission:System: Read User Kerberos Ticket Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permissions for location 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Add IPA Locations 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Add IPA Locations 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Add IPA Locations";allow (add) groupdn = "ldap:///cn=System: Add IPA Locations,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=locations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Modify IPA Locations 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Modify IPA Locations 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "description")(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Modify IPA Locations";allow (write) groupdn = "ldap:///cn=System: Modify IPA Locations,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=locations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read IPA Locations 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read IPA Locations 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "createtimestamp || description || entryusn || idnsname || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Read IPA Locations";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Locations,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=locations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Remove IPA Locations 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Remove IPA Locations 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Remove IPA Locations";allow (delete) groupdn = "ldap:///cn=System: Remove IPA Locations,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=locations,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permissions for netgroup 2020-06-17T10:11:15Z DEBUG Legacy permission Add netgroups not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Add Netgroups 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Add Netgroups 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Add Netgroups";allow (add) groupdn = "ldap:///cn=System: Add Netgroups,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=ng,cn=alt,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Legacy permission Modify netgroup membership not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Modify Netgroup Membership 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Modify Netgroup Membership 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "externalhost || member || memberhost || memberuser")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroup Membership";allow (write) groupdn = "ldap:///cn=System: Modify Netgroup Membership,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=ng,cn=alt,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Legacy permission Modify netgroups not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Modify Netgroups 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Modify Netgroups 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "description")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroups";allow (write) groupdn = "ldap:///cn=System: Modify Netgroups,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=ng,cn=alt,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read Netgroup Compat Tree 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read Netgroup Compat Tree 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=lin,dc=test,dc=lan")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read Netgroup Membership 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read Netgroup Membership 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "createtimestamp || entryusn || externalhost || member || memberhost || memberof || memberuser || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroup Membership";allow (compare,read,search) userdn = "ldap:///all";)' to cn=ng,cn=alt,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read Netgroups 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read Netgroups 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || hostcategory || ipaenabledflag || ipauniqueid || modifytimestamp || nisdomainname || objectclass || usercategory")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroups";allow (compare,read,search) userdn = "ldap:///all";)' to cn=ng,cn=alt,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Legacy permission Remove netgroups not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Remove Netgroups 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Remove Netgroups 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Remove Netgroups";allow (delete) groupdn = "ldap:///cn=System: Remove Netgroups,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=ng,cn=alt,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permissions for otpconfig 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read OTP Configuration 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read OTP Configuration 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "cn || ipatokenhotpauthwindow || ipatokenhotpsyncwindow || ipatokentotpauthwindow || ipatokentotpsyncwindow")(targetfilter = "(objectclass=ipatokenotpconfig)")(version 3.0;acl "permission:System: Read OTP Configuration";allow (compare,read,search) userdn = "ldap:///all";)' to cn=otp,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permissions for permission 2020-06-17T10:11:15Z DEBUG Legacy permission Modify privilege membership not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Modify Privilege Membership 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Modify Privilege Membership 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "member")(targetfilter = "(objectclass=ipapermission)")(version 3.0;acl "permission:System: Modify Privilege Membership";allow (write) groupdn = "ldap:///cn=System: Modify Privilege Membership,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read ACIs 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read ACIs 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read Permissions 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read Permissions 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || ipapermbindruletype || ipapermdefaultattr || ipapermexcludedattr || ipapermincludedattr || ipapermissiontype || ipapermlocation || ipapermright || ipapermtarget || ipapermtargetfilter || member || memberhost || memberof || memberuser || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=ipapermission)")(version 3.0;acl "permission:System: Read Permissions";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Permissions,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permissions for privilege 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Add Privileges 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Add Privileges 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Add Privileges";allow (add) groupdn = "ldap:///cn=System: Add Privileges,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Modify Privileges 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Modify Privileges 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "businesscategory || cn || description || o || ou || owner || seealso")(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Modify Privileges";allow (write) groupdn = "ldap:///cn=System: Modify Privileges,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read Privileges 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read Privileges 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || member || memberhost || memberof || memberuser || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Read Privileges";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Privileges,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Remove Privileges 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Remove Privileges 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Remove Privileges";allow (delete) groupdn = "ldap:///cn=System: Remove Privileges,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=privileges,cn=pbac,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permissions for pwpolicy 2020-06-17T10:11:15Z DEBUG Legacy permission Add Group Password Policy not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Add Group Password Policy 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Add Group Password Policy 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Add Group Password Policy";allow (add) groupdn = "ldap:///cn=System: Add Group Password Policy,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Legacy permission Delete Group Password Policy not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Delete Group Password Policy 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Delete Group Password Policy 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Delete Group Password Policy";allow (delete) groupdn = "ldap:///cn=System: Delete Group Password Policy,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Legacy permission Modify Group Password Policy not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Modify Group Password Policy 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Modify Group Password Policy 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "krbmaxpwdlife || krbminpwdlife || krbpwdfailurecountinterval || krbpwdhistorylength || krbpwdlockoutduration || krbpwdmaxfailure || krbpwdmindiffchars || krbpwdminlength")(targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Modify Group Password Policy";allow (write) groupdn = "ldap:///cn=System: Modify Group Password Policy,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read Group Password Policy 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read Group Password Policy 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "cn || cospriority || createtimestamp || entryusn || krbmaxpwdlife || krbminpwdlife || krbpwdfailurecountinterval || krbpwdhistorylength || krbpwdlockoutduration || krbpwdmaxfailure || krbpwdmindiffchars || krbpwdminlength || modifytimestamp || objectclass")(targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Read Group Password Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=LIN.TEST.LAN,cn=kerberos,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permissions for radiusproxy 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read Radius Servers 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read Radius Servers 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || ipatokenradiusretries || ipatokenradiusserver || ipatokenradiustimeout || ipatokenusermapattribute || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipatokenradiusconfiguration)")(version 3.0;acl "permission:System: Read Radius Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Radius Servers,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=radiusproxy,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permissions for realmdomains 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Modify Realm Domains 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Modify Realm Domains 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "associateddomain")(targetfilter = "(objectclass=domainrelatedobject)")(version 3.0;acl "permission:System: Modify Realm Domains";allow (write) groupdn = "ldap:///cn=System: Modify Realm Domains,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=Realm Domains,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read Realm Domains 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read Realm Domains 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "associateddomain || cn || createtimestamp || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=domainrelatedobject)")(version 3.0;acl "permission:System: Read Realm Domains";allow (compare,read,search) userdn = "ldap:///all";)' to cn=Realm Domains,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permissions for role 2020-06-17T10:11:15Z DEBUG Legacy permission Add Roles not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Add Roles 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Add Roles 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Add Roles";allow (add) groupdn = "ldap:///cn=System: Add Roles,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Legacy permission Modify Role membership not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Modify Role Membership 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Modify Role Membership 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "member")(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Modify Role Membership";allow (write) groupdn = "ldap:///cn=System: Modify Role Membership,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Legacy permission Modify Roles not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Modify Roles 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Modify Roles 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "cn || description")(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Modify Roles";allow (write) groupdn = "ldap:///cn=System: Modify Roles,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read Roles 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read Roles 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || member || memberhost || memberof || memberuser || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Read Roles";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Roles,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Legacy permission Remove Roles not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Remove Roles 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Remove Roles 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Remove Roles";allow (delete) groupdn = "ldap:///cn=System: Remove Roles,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=roles,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permissions for selinuxusermap 2020-06-17T10:11:15Z DEBUG Legacy permission Add SELinux User Maps not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Add SELinux User Maps 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Add SELinux User Maps 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Add SELinux User Maps";allow (add) groupdn = "ldap:///cn=System: Add SELinux User Maps,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=usermap,cn=selinux,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Legacy permission Modify SELinux User Maps not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Modify SELinux User Maps 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Modify SELinux User Maps 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "cn || ipaenabledflag || ipaselinuxuser || memberhost || memberuser || seealso")(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Modify SELinux User Maps";allow (write) groupdn = "ldap:///cn=System: Modify SELinux User Maps,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=usermap,cn=selinux,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read SELinux User Maps 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read SELinux User Maps 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "accesstime || cn || createtimestamp || description || entryusn || hostcategory || ipaenabledflag || ipaselinuxuser || ipauniqueid || member || memberhost || memberuser || modifytimestamp || objectclass || seealso || usercategory")(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Read SELinux User Maps";allow (compare,read,search) userdn = "ldap:///all";)' to cn=usermap,cn=selinux,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Legacy permission Remove SELinux User Maps not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Remove SELinux User Maps 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Remove SELinux User Maps 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Remove SELinux User Maps";allow (delete) groupdn = "ldap:///cn=System: Remove SELinux User Maps,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=usermap,cn=selinux,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permissions for server 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read Locations of IPA Servers 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read Locations of IPA Servers 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read Status of Services on IPA Servers 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read Status of Services on IPA Servers 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permissions for service 2020-06-17T10:11:15Z DEBUG Legacy permission Add Services not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Add Services 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Add Services 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Legacy permission Manage service keytab not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Manage Service Keytab 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Manage Service Keytab 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Manage Service Keytab Permissions 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Manage Service Keytab Permissions 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Manage Service Principals 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Manage Service Principals 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Legacy permission Modify Services not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Modify Services 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Modify Services 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read POSIX details of SMB services 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read POSIX details of SMB services 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read POSIX details of SMB services";allow (compare,read,search) userdn = "ldap:///all";)' to cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Read Services 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Read Services 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";)' to cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Legacy permission Remove Services not found 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Remove Services 2020-06-17T10:11:15Z DEBUG Updating ACI for managed permission: System: Remove Services 2020-06-17T10:11:15Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=services,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:15Z DEBUG Updating managed permissions for servicedelegationrule 2020-06-17T10:11:15Z DEBUG Updating managed permission: System: Add Service Delegations 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Add Service Delegations 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Add Service Delegations";allow (add) groupdn = "ldap:///cn=System: Add Service Delegations,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Modify Service Delegation Membership 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Modify Service Delegation Membership 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "ipaallowedtarget || memberprincipal")(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Modify Service Delegation Membership";allow (write) groupdn = "ldap:///cn=System: Modify Service Delegation Membership,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Read Service Delegations 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Read Service Delegations 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || ipaallowedtarget || memberprincipal || modifytimestamp || objectclass")(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Read Service Delegations";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Service Delegations,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Remove Service Delegations 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Remove Service Delegations 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Remove Service Delegations";allow (delete) groupdn = "ldap:///cn=System: Remove Service Delegations,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=s4u2proxy,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permissions for servicedelegationtarget 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Add Service Delegations 2020-06-17T10:11:16Z DEBUG No changes to permission: System: Add Service Delegations 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Modify Service Delegation Membership 2020-06-17T10:11:16Z DEBUG No changes to permission: System: Modify Service Delegation Membership 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Read Service Delegations 2020-06-17T10:11:16Z DEBUG No changes to permission: System: Read Service Delegations 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Remove Service Delegations 2020-06-17T10:11:16Z DEBUG No changes to permission: System: Remove Service Delegations 2020-06-17T10:11:16Z DEBUG Updating managed permissions for stageuser 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Add Stage User 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Add Stage User 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Add Stage User";allow (add) groupdn = "ldap:///cn=System: Add Stage User,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Modify Preserved Users 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Modify Preserved Users 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Preserved Users";allow (write) groupdn = "ldap:///cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=deleted users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Modify Stage User 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Modify Stage User 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Modify Stage User";allow (write) groupdn = "ldap:///cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Modify User RDN 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Modify User RDN 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "uid")(target = "ldap:///uid=*,cn=users,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify User RDN";allow (write) groupdn = "ldap:///cn=System: Modify User RDN,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Preserve User 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Preserve User 2020-06-17T10:11:16Z DEBUG Adding ACI '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan")(target_from = "ldap:///cn=users,cn=accounts,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Read Preserved Users 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Read Preserved Users 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read Preserved Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=deleted users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Read Stage User password 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Read Stage User password 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage User password";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Read Stage Users 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Read Stage Users 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Remove Stage User 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Remove Stage User 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove Stage User";allow (delete) groupdn = "ldap:///cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=staged users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Remove preserved User 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Remove preserved User 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove preserved User";allow (delete) groupdn = "ldap:///cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=deleted users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Reset Preserved User password 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Reset Preserved User password 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "krblastpwdchange || krbpasswordexpiration || krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Reset Preserved User password";allow (read,search,write) groupdn = "ldap:///cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=deleted users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Undelete User 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Undelete User 2020-06-17T10:11:16Z DEBUG Adding ACI '(target_to = "ldap:///cn=users,cn=accounts,dc=lin,dc=test,dc=lan")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permissions for sudocmd 2020-06-17T10:11:16Z DEBUG Legacy permission Add Sudo command not found 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Add Sudo Command 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Add Sudo Command 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipasudocmd)")(version 3.0;acl "permission:System: Add Sudo Command";allow (add) groupdn = "ldap:///cn=System: Add Sudo Command,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=sudocmds,cn=sudo,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Legacy permission Delete Sudo command not found 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Delete Sudo Command 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Delete Sudo Command 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipasudocmd)")(version 3.0;acl "permission:System: Delete Sudo Command";allow (delete) groupdn = "ldap:///cn=System: Delete Sudo Command,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=sudocmds,cn=sudo,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Legacy permission Modify Sudo command not found 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Modify Sudo Command 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Modify Sudo Command 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "description")(targetfilter = "(objectclass=ipasudocmd)")(version 3.0;acl "permission:System: Modify Sudo Command";allow (write) groupdn = "ldap:///cn=System: Modify Sudo Command,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=sudocmds,cn=sudo,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Read Sudo Commands 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Read Sudo Commands 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "createtimestamp || description || entryusn || ipauniqueid || memberof || modifytimestamp || objectclass || sudocmd")(targetfilter = "(objectclass=ipasudocmd)")(version 3.0;acl "permission:System: Read Sudo Commands";allow (compare,read,search) userdn = "ldap:///all";)' to cn=sudocmds,cn=sudo,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permissions for sudocmdgroup 2020-06-17T10:11:16Z DEBUG Legacy permission Add Sudo command group not found 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Add Sudo Command Group 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Add Sudo Command Group 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipasudocmdgrp)")(version 3.0;acl "permission:System: Add Sudo Command Group";allow (add) groupdn = "ldap:///cn=System: Add Sudo Command Group,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=sudocmdgroups,cn=sudo,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Legacy permission Delete Sudo command group not found 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Delete Sudo Command Group 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Delete Sudo Command Group 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipasudocmdgrp)")(version 3.0;acl "permission:System: Delete Sudo Command Group";allow (delete) groupdn = "ldap:///cn=System: Delete Sudo Command Group,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=sudocmdgroups,cn=sudo,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Legacy permission Manage Sudo command group membership not found 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Manage Sudo Command Group Membership 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Manage Sudo Command Group Membership 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "member")(targetfilter = "(objectclass=ipasudocmdgrp)")(version 3.0;acl "permission:System: Manage Sudo Command Group Membership";allow (write) groupdn = "ldap:///cn=System: Manage Sudo Command Group Membership,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=sudocmdgroups,cn=sudo,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Modify Sudo Command Group 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Modify Sudo Command Group 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "description")(targetfilter = "(objectclass=ipasudocmdgrp)")(version 3.0;acl "permission:System: Modify Sudo Command Group";allow (write) groupdn = "ldap:///cn=System: Modify Sudo Command Group,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=sudocmdgroups,cn=sudo,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Read Sudo Command Groups 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Read Sudo Command Groups 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || ipauniqueid || member || memberhost || memberuser || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=ipasudocmdgrp)")(version 3.0;acl "permission:System: Read Sudo Command Groups";allow (compare,read,search) userdn = "ldap:///all";)' to cn=sudocmdgroups,cn=sudo,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permissions for sudorule 2020-06-17T10:11:16Z DEBUG Legacy permission Add Sudo rule not found 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Add Sudo rule 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Add Sudo rule 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipasudorule)")(version 3.0;acl "permission:System: Add Sudo rule";allow (add) groupdn = "ldap:///cn=System: Add Sudo rule,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=sudorules,cn=sudo,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Legacy permission Delete Sudo rule not found 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Delete Sudo rule 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Delete Sudo rule 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipasudorule)")(version 3.0;acl "permission:System: Delete Sudo rule";allow (delete) groupdn = "ldap:///cn=System: Delete Sudo rule,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=sudorules,cn=sudo,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Legacy permission Modify Sudo rule not found 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Modify Sudo rule 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Modify Sudo rule 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "cmdcategory || description || externalhost || externaluser || hostcategory || hostmask || ipaenabledflag || ipasudoopt || ipasudorunas || ipasudorunasextgroup || ipasudorunasextuser || ipasudorunasextusergroup || ipasudorunasgroup || ipasudorunasgroupcategory || ipasudorunasusercategory || memberallowcmd || memberdenycmd || memberhost || memberuser || sudonotafter || sudonotbefore || sudoorder || usercategory")(targetfilter = "(objectclass=ipasudorule)")(version 3.0;acl "permission:System: Modify Sudo rule";allow (write) groupdn = "ldap:///cn=System: Modify Sudo rule,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=sudorules,cn=sudo,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Read Sudo Rules 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Read Sudo Rules 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "cmdcategory || cn || createtimestamp || description || entryusn || externalhost || externaluser || hostcategory || hostmask || ipaenabledflag || ipasudoopt || ipasudorunas || ipasudorunasextgroup || ipasudorunasextuser || ipasudorunasextusergroup || ipasudorunasgroup || ipasudorunasgroupcategory || ipasudorunasusercategory || ipauniqueid || member || memberallowcmd || memberdenycmd || memberhost || memberuser || modifytimestamp || objectclass || sudonotafter || sudonotbefore || sudoorder || usercategory")(targetfilter = "(objectclass=ipasudorule)")(version 3.0;acl "permission:System: Read Sudo Rules";allow (compare,read,search) userdn = "ldap:///all";)' to cn=sudorules,cn=sudo,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Read Sudoers compat tree 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Read Sudoers compat tree 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=lin,dc=test,dc=lan")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permissions for trust 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Read Trust Information 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Read Trust Information 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)' to cn=trusts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Read system trust accounts 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Read system trust accounts 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=trusts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permissions for user 2020-06-17T10:11:16Z DEBUG Legacy permission Add user to default group not found 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Add User to default group 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Add User to default group 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "member")(target = "ldap:///cn=ipausers,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan")(version 3.0;acl "permission:System: Add User to default group";allow (write) groupdn = "ldap:///cn=System: Add User to default group,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=groups,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Legacy permission Add Users not found 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Add Users 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Add Users 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Add Users";allow (add) groupdn = "ldap:///cn=System: Add Users,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Legacy permission Change a user password not found 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Change User password 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Change User password 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "krbpasswordexpiration || krbprincipalkey || passwordhistory || sambalmpassword || sambantpassword || userpassword")(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Change User password";allow (write) groupdn = "ldap:///cn=System: Change User password,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Manage User Certificate Mappings 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Manage User Certificate Mappings 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "ipacertmapdata || objectclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Certificate Mappings";allow (write) groupdn = "ldap:///cn=System: Manage User Certificate Mappings,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Manage User Certificates 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Manage User Certificates 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "usercertificate")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Certificates";allow (write) groupdn = "ldap:///cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Manage User Principals 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Manage User Principals 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Principals";allow (write) groupdn = "ldap:///cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Legacy permission Manage User SSH Public Keys not found 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Manage User SSH Public Keys 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Manage User SSH Public Keys 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "ipasshpubkey")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage User SSH Public Keys,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Legacy permission Modify Users not found 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Modify Users 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Modify Users 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "businesscategory || carlicense || cn || departmentnumber || description || displayname || employeenumber || employeetype || facsimiletelephonenumber || gecos || givenname || homedirectory || homephone || inetuserhttpurl || initials || l || labeleduri || loginshell || mail || manager || mepmanagedentry || mobile || objectclass || ou || pager || postalcode || preferredlanguage || roomnumber || secretary || seealso || sn || st || street || telephonenumber || title || userclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Users";allow (write) groupdn = "ldap:///cn=System: Modify Users,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Read UPG Definition 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Read UPG Definition 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "*")(target = "ldap:///cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan")(version 3.0;acl "permission:System: Read UPG Definition";allow (compare,read,search) groupdn = "ldap:///cn=System: Read UPG Definition,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Read User Addressbook Attributes 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Read User Addressbook Attributes 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "audio || businesscategory || carlicense || departmentnumber || destinationindicator || employeenumber || employeetype || facsimiletelephonenumber || homephone || homepostaladdress || inetuserhttpurl || inetuserstatus || internationalisdnnumber || ipacertmapdata || jpegphoto || l || labeleduri || mail || mobile || o || ou || pager || photo || physicaldeliveryofficename || postaladdress || postalcode || postofficebox || preferreddeliverymethod || preferredlanguage || registeredaddress || roomnumber || secretary || seealso || st || street || telephonenumber || teletexterminalidentifier || telexnumber || usercertificate || usersmimecertificate || x121address || x500uniqueidentifier")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Addressbook Attributes";allow (compare,read,search) userdn = "ldap:///all";)' to cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Read User Compat Tree 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Read User Compat Tree 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=lin,dc=test,dc=lan")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Read User IPA Attributes 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Read User IPA Attributes 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "ipasshpubkey || ipauniqueid || ipauserauthtype || userclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User IPA Attributes";allow (compare,read,search) userdn = "ldap:///all";)' to cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Read User Kerberos Attributes 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Read User Kerberos Attributes 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalexpiration || krbprincipalname || krbprincipaltype || nsaccountlock")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Kerberos Attributes";allow (compare,read,search) userdn = "ldap:///all";)' to cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:16Z DEBUG Updating managed permission: System: Read User Kerberos Login Attributes 2020-06-17T10:11:16Z DEBUG Updating ACI for managed permission: System: Read User Kerberos Login Attributes 2020-06-17T10:11:16Z DEBUG Adding ACI '(targetattr = "krblastadminunlock || krblastfailedauth || krblastpwdchange || krblastsuccessfulauth || krbloginfailedcount || krbpwdpolicyreference || krbticketpolicyreference || krbupenabled")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Kerberos Login Attributes";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Login Attributes,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Read User Membership 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Read User Membership 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "memberof")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Membership";allow (compare,read,search) userdn = "ldap:///all";)' to cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Read User NT Attributes 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Read User NT Attributes 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "ntuniqueid || ntuseracctexpires || ntusercodepage || ntuserdeleteaccount || ntuserdomainid || ntuserlastlogoff || ntuserlastlogon")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User NT Attributes";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User NT Attributes,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Read User Standard Attributes 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Read User Standard Attributes 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || initials || ipantsecurityidentifier || loginshell || manager || modifytimestamp || objectclass || sn || title || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Standard Attributes";allow (compare,read,search) userdn = "ldap:///anyone";)' to cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Read User Views Compat Tree 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Read User Views Compat Tree 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=lin,dc=test,dc=lan")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Legacy permission Remove Users not found 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Remove Users 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Remove Users 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Remove Users";allow (delete) groupdn = "ldap:///cn=System: Remove Users,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Legacy permission Unlock user accounts not found 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Unlock User 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Unlock User 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "krblastadminunlock || krbloginfailedcount || nsaccountlock")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Unlock User";allow (write) groupdn = "ldap:///cn=System: Unlock User,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=users,cn=accounts,dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permissions for vault 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Add Vaults 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Add Vaults 2020-06-17T10:11:17Z DEBUG Adding ACI '(target = "ldap:///cn=vaults,cn=kra,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Delete Vaults 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Delete Vaults 2020-06-17T10:11:17Z DEBUG Adding ACI '(target = "ldap:///cn=vaults,cn=kra,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Manage Vault Membership 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Manage Vault Membership 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Manage Vault Ownership 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Manage Vault Ownership 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Modify Vaults 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Modify Vaults 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Read Vaults 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Read Vaults 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permissions for vaultcontainer 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Add Vault Containers 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Add Vault Containers 2020-06-17T10:11:17Z DEBUG Adding ACI '(target = "ldap:///cn=vaults,cn=kra,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Delete Vault Containers 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Delete Vault Containers 2020-06-17T10:11:17Z DEBUG Adding ACI '(target = "ldap:///cn=vaults,cn=kra,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Manage Vault Container Ownership 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Manage Vault Container Ownership 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Modify Vault Containers 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Modify Vault Containers 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Read Vault Containers 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Read Vault Containers 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating non-object managed permissions 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Add CA Certificate For Renewal 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Add CA Certificate For Renewal 2020-06-17T10:11:17Z DEBUG Adding ACI '(target = "ldap:///cn=caSigningCert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Add CA Certificate For Renewal";allow (add) groupdn = "ldap:///cn=System: Add CA Certificate For Renewal,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Add Certificate Store Entry 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Add Certificate Store Entry 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Add Certificate Store Entry";allow (add) groupdn = "ldap:///cn=System: Add Certificate Store Entry,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=certificates,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Compat Tree ID View targets 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Compat Tree ID View targets 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Modify CA Certificate 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Modify CA Certificate 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "cacertificate")(targetfilter = "(objectclass=pkica)")(version 3.0;acl "permission:System: Modify CA Certificate";allow (write) groupdn = "ldap:///cn=System: Modify CA Certificate,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=CAcert,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Modify CA Certificate For Renewal 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Modify CA Certificate For Renewal 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "usercertificate")(target = "ldap:///cn=caSigningCert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Modify CA Certificate For Renewal";allow (write) groupdn = "ldap:///cn=System: Modify CA Certificate For Renewal,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Modify Certificate Store Entry 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Modify Certificate Store Entry 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "cacertificate || ipacertissuerserial || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Modify Certificate Store Entry";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Store Entry,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=certificates,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Read AD Domains 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Read AD Domains 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || ipantdomainguid || ipantfallbackprimarygroup || ipantflatname || ipantsecurityidentifier || modifytimestamp || objectclass")(target = "ldap:///cn=ad,cn=etc,dc=lin,dc=test,dc=lan")(targetfilter = "(objectclass=ipantdomainattrs)")(version 3.0;acl "permission:System: Read AD Domains";allow (compare,read,search) userdn = "ldap:///all";)' to cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Read CA Certificate 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Read CA Certificate 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "authorityrevocationlist || cacertificate || certificaterevocationlist || cn || createtimestamp || crosscertificatepair || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=pkica)")(version 3.0;acl "permission:System: Read CA Certificate";allow (compare,read,search) userdn = "ldap:///anyone";)' to cn=CAcert,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Read CA Renewal Information 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Read CA Renewal Information 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Read CA Renewal Information";allow (compare,read,search) userdn = "ldap:///all";)' to cn=ca_renewal,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Read Certificate Store Entries 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Read Certificate Store Entries 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "cacertificate || cn || createtimestamp || entryusn || ipacertissuerserial || ipacertsubject || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage || ipapublickey || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Read Certificate Store Entries";allow (compare,read,search) userdn = "ldap:///anyone";)' to cn=certificates,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Read DNA Configuration 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Read DNA Configuration 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || dnahostname || dnaportnum || dnaremainingvalues || dnaremotebindmethod || dnaremoteconnprotocol || dnasecureportnum || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=dnasharedconfig)")(version 3.0;acl "permission:System: Read DNA Configuration";allow (compare,read,search) userdn = "ldap:///all";)' to cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Read DUA Profile 2020-06-17T10:11:17Z DEBUG Updating ACI for managed permission: System: Read DUA Profile 2020-06-17T10:11:17Z DEBUG Adding ACI '(targetattr = "attributemap || authenticationmethod || bindtimelimit || cn || createtimestamp || credentiallevel || defaultsearchbase || defaultsearchscope || defaultserverlist || dereferencealiases || entryusn || followreferrals || modifytimestamp || objectclass || objectclassmap || ou || preferredserverlist || profilettl || searchtimelimit || serviceauthenticationmethod || servicecredentiallevel || servicesearchdescriptor")(targetfilter = "(|(objectclass=organizationalUnit)(objectclass=DUAConfigProfile))")(version 3.0;acl "permission:System: Read DUA Profile";allow (compare,read,search) userdn = "ldap:///anyone";)' to ou=profile,dc=lin,dc=test,dc=lan 2020-06-17T10:11:17Z DEBUG Updating managed permission: System: Read Domain Level 2020-06-17T10:11:18Z DEBUG Updating ACI for managed permission: System: Read Domain Level 2020-06-17T10:11:18Z DEBUG Adding ACI '(targetattr = "createtimestamp || entryusn || ipadomainlevel || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipadomainlevelconfig)")(version 3.0;acl "permission:System: Read Domain Level";allow (compare,read,search) userdn = "ldap:///all";)' to cn=Domain Level,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:18Z DEBUG Updating managed permission: System: Read IPA Masters 2020-06-17T10:11:18Z DEBUG Updating ACI for managed permission: System: Read IPA Masters 2020-06-17T10:11:18Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=masters,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:18Z DEBUG Updating managed permission: System: Read Replication Information 2020-06-17T10:11:18Z DEBUG Updating ACI for managed permission: System: Read Replication Information 2020-06-17T10:11:18Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicachangecount || nsds5replicacleanruv || nsds5replicaid || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicatombstonepurgeinterval || nsds5replicatype || nsds5task || nsstate || objectclass")(targetfilter = "(objectclass=nsds5replica)")(version 3.0;acl "permission:System: Read Replication Information";allow (compare,read,search) userdn = "ldap:///all";)' to cn=replication,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:18Z DEBUG Updating managed permission: System: Remove Certificate Store Entry 2020-06-17T10:11:18Z DEBUG Updating ACI for managed permission: System: Remove Certificate Store Entry 2020-06-17T10:11:18Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Remove Certificate Store Entry";allow (delete) groupdn = "ldap:///cn=System: Remove Certificate Store Entry,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan";)' to cn=certificates,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan 2020-06-17T10:11:18Z DEBUG Deleting obsolete permission System: Read Creator and Modifier Operational Attributes 2020-06-17T10:11:18Z DEBUG raw: permission_del(('System: Read Creator and Modifier Operational Attributes',), force=True, version='2.101') 2020-06-17T10:11:18Z DEBUG permission_del(('System: Read Creator and Modifier Operational Attributes',), continue=False, force=True, version='2.101') 2020-06-17T10:11:18Z DEBUG Obsolete permission not found 2020-06-17T10:11:18Z DEBUG Deleting obsolete permission System: Read Timestamp and USN Operational Attributes 2020-06-17T10:11:18Z DEBUG raw: permission_del(('System: Read Timestamp and USN Operational Attributes',), force=True, version='2.101') 2020-06-17T10:11:18Z DEBUG permission_del(('System: Read Timestamp and USN Operational Attributes',), continue=False, force=True, version='2.101') 2020-06-17T10:11:18Z DEBUG Obsolete permission not found 2020-06-17T10:11:18Z DEBUG Executing upgrade plugin: update_read_replication_agreements_permission 2020-06-17T10:11:18Z DEBUG raw: update_read_replication_agreements_permission 2020-06-17T10:11:18Z DEBUG Old permission not found 2020-06-17T10:11:18Z DEBUG Executing upgrade plugin: update_idrange_baserid 2020-06-17T10:11:18Z DEBUG raw: update_idrange_baserid 2020-06-17T10:11:18Z DEBUG update_idrange_baserid: search for ipa-ad-trust-posix ID ranges with ipaBaseRID != 0 2020-06-17T10:11:18Z DEBUG update_idrange_baserid: no AD domain range with posix attributes found 2020-06-17T10:11:18Z DEBUG Executing upgrade plugin: update_passync_privilege_update 2020-06-17T10:11:18Z DEBUG raw: update_passync_privilege_update 2020-06-17T10:11:18Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:11:18Z DEBUG Add PassSync user as a member of PassSync privilege 2020-06-17T10:11:18Z DEBUG PassSync user not found, no update needed 2020-06-17T10:11:18Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:11:18Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:11:18Z DEBUG Executing upgrade plugin: update_dnsserver_configuration_into_ldap 2020-06-17T10:11:18Z DEBUG raw: update_dnsserver_configuration_into_ldap 2020-06-17T10:11:18Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:11:18Z DEBUG DNS container not found, nothing to upgrade 2020-06-17T10:11:18Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:11:18Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:11:18Z DEBUG Executing upgrade plugin: update_ldap_server_list 2020-06-17T10:11:18Z DEBUG raw: update_ldap_server_list 2020-06-17T10:11:18Z DEBUG Executing upgrade plugin: update_dna_shared_config 2020-06-17T10:11:18Z DEBUG raw: update_dna_shared_config 2020-06-17T10:11:18Z DEBUG 2 entries dnaHostname=freeipaserver.lin.test.lan under cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=lin,dc=test,dc=lan. One expected 2020-06-17T10:11:18Z DEBUG Executing upgrade plugin: update_unhashed_password 2020-06-17T10:11:18Z DEBUG raw: update_unhashed_password 2020-06-17T10:11:18Z DEBUG Upgrading unhashed password configuration 2020-06-17T10:11:18Z DEBUG Unhashed password this is not a winsync deployment 2020-06-17T10:11:18Z DEBUG LDAP update duration: /usr/share/ipa/updates/90-post_upgrade_plugins.update 9.447 sec 2020-06-17T10:11:18Z DEBUG Destroyed connection context.ldap2_139849980197240 2020-06-17T10:11:18Z DEBUG step duration: dirsrv __upgrade 26.64 sec 2020-06-17T10:11:18Z DEBUG [8/10]: stopping directory server 2020-06-17T10:11:18Z DEBUG Destroyed connection context.ldap2_139850008098072 2020-06-17T10:11:18Z DEBUG Starting external process 2020-06-17T10:11:18Z DEBUG args=['/bin/systemctl', 'stop', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:11:20Z DEBUG Process finished, return code=0 2020-06-17T10:11:20Z DEBUG stdout= 2020-06-17T10:11:20Z DEBUG stderr= 2020-06-17T10:11:20Z DEBUG Stop of dirsrv@LIN-TEST-LAN.service complete 2020-06-17T10:11:20Z DEBUG step duration: dirsrv __stop_instance 2.52 sec 2020-06-17T10:11:20Z DEBUG [9/10]: restoring configuration 2020-06-17T10:11:20Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:20Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:20Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:20Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:20Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:20Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:20Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:20Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:20Z DEBUG step duration: dirsrv __restore_config 0.09 sec 2020-06-17T10:11:20Z DEBUG [10/10]: starting directory server 2020-06-17T10:11:20Z DEBUG Starting external process 2020-06-17T10:11:20Z DEBUG args=['/bin/systemctl', 'start', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:11:22Z DEBUG Process finished, return code=0 2020-06-17T10:11:22Z DEBUG stdout= 2020-06-17T10:11:22Z DEBUG stderr= 2020-06-17T10:11:22Z DEBUG Start of dirsrv@LIN-TEST-LAN.service complete 2020-06-17T10:11:22Z DEBUG Created connection context.ldap2_139850008098072 2020-06-17T10:11:22Z DEBUG step duration: dirsrv __start 1.62 sec 2020-06-17T10:11:22Z DEBUG Done. 2020-06-17T10:11:22Z DEBUG service duration: dirsrv 37.95 sec 2020-06-17T10:11:22Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:11:22Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:11:22Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:11:22Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:11:22Z DEBUG Restarting the KDC 2020-06-17T10:11:22Z DEBUG Starting external process 2020-06-17T10:11:22Z DEBUG args=['/bin/systemctl', 'restart', 'krb5kdc.service'] 2020-06-17T10:11:22Z DEBUG Process finished, return code=0 2020-06-17T10:11:22Z DEBUG stdout= 2020-06-17T10:11:22Z DEBUG stderr= 2020-06-17T10:11:22Z DEBUG Starting external process 2020-06-17T10:11:22Z DEBUG args=['/bin/systemctl', 'is-active', 'krb5kdc.service'] 2020-06-17T10:11:22Z DEBUG Process finished, return code=0 2020-06-17T10:11:22Z DEBUG stdout=active 2020-06-17T10:11:22Z DEBUG stderr= 2020-06-17T10:11:22Z DEBUG Restart of krb5kdc.service complete 2020-06-17T10:11:22Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:11:22Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:22Z DEBUG Starting external process 2020-06-17T10:11:22Z DEBUG args=['/bin/systemctl', 'stop', 'named-pkcs11.service'] 2020-06-17T10:11:22Z DEBUG Process finished, return code=0 2020-06-17T10:11:22Z DEBUG stdout= 2020-06-17T10:11:22Z DEBUG stderr= 2020-06-17T10:11:22Z DEBUG Stop of named-pkcs11.service complete 2020-06-17T10:11:22Z DEBUG raw: dnszone_show('lin.test.lan', version='2.235') 2020-06-17T10:11:22Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:22Z DEBUG Configuring DNS (named) 2020-06-17T10:11:22Z DEBUG [1/11]: generating rndc key file 2020-06-17T10:11:22Z DEBUG Starting external process 2020-06-17T10:11:22Z DEBUG args=['/usr/libexec/generate-rndc-key.sh'] 2020-06-17T10:11:22Z DEBUG Process finished, return code=0 2020-06-17T10:11:22Z DEBUG stdout=Generating /etc/rndc.key:[ OK ] 2020-06-17T10:11:22Z DEBUG stderr= 2020-06-17T10:11:22Z DEBUG step duration: named __generate_rndc_key 0.03 sec 2020-06-17T10:11:22Z DEBUG [2/11]: adding DNS container 2020-06-17T10:11:22Z DEBUG Starting external process 2020-06-17T10:11:22Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp8jrientu', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:11:22Z DEBUG Process finished, return code=0 2020-06-17T10:11:22Z DEBUG stdout=add objectClass: idnsConfigObject nsContainer ipaConfigObject ipaDNSContainer top add cn: dns add ipaConfigString: DNSVersion 1 add ipaDNSVersion: 2 add aci: (targetattr = "*")(version 3.0; acl "Allow read access"; allow (read,search,compare) groupdn = "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=lin,dc=test,dc=lan" or userattr = "parent[0,1].managedby#GROUPDN";) (target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";) (target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";) (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=lin,dc=test,dc=lan")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";) adding new entry "cn=dns,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top add cn: servers adding new entry "cn=servers,cn=dns,dc=lin,dc=test,dc=lan" modify complete 2020-06-17T10:11:22Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:11:22Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket from SchemaCache 2020-06-17T10:11:22Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:11:23Z DEBUG step duration: named __setup_dns_container 1.49 sec 2020-06-17T10:11:23Z DEBUG [3/11]: setting up our zone 2020-06-17T10:11:23Z DEBUG raw: dnszone_add('lin.test.lan.', idnssoamname='freeipaserver.lin.test.lan.', idnssoarname='hostmaster.lin.test.lan.', idnsupdatepolicy='grant LIN.TEST.LAN krb5-self * A; grant LIN.TEST.LAN krb5-self * AAAA; grant LIN.TEST.LAN krb5-self * SSHFP;', idnsallowdynupdate=True, idnsallowquery='any', idnsallowtransfer='none', skip_overlap_check=True, force=True, version='2.235') 2020-06-17T10:11:23Z DEBUG dnszone_add(, idnssoamname=, idnssoarname=, idnssoaserial=1592388683, idnssoarefresh=3600, idnssoaretry=900, idnssoaexpire=1209600, idnssoaminimum=3600, idnsupdatepolicy='grant LIN.TEST.LAN krb5-self * A; grant LIN.TEST.LAN krb5-self * AAAA; grant LIN.TEST.LAN krb5-self * SSHFP;', idnsallowdynupdate=True, idnsallowquery='any;', idnsallowtransfer='none;', skip_overlap_check=True, force=True, skip_nameserver_check=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:23Z DEBUG raw: dnsrecord_add('lin.test.lan', '_kerberos', txtrecord='LIN.TEST.LAN', version='2.235') 2020-06-17T10:11:23Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, txtrecord=('LIN.TEST.LAN',), force=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:23Z DEBUG step duration: named __setup_zone 0.05 sec 2020-06-17T10:11:23Z DEBUG [4/11]: setting up our own record 2020-06-17T10:11:23Z DEBUG raw: dnszone_show('lin.test.lan', version='2.235') 2020-06-17T10:11:23Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:23Z DEBUG raw: dnsrecord_add('lin.test.lan', 'freeipaserver', arecord='10.0.0.179', version='2.235') 2020-06-17T10:11:23Z DEBUG dnsrecord_add(, , arecord=('10.0.0.179',), a_extra_create_reverse=False, aaaa_extra_create_reverse=False, force=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:24Z DEBUG raw: dnszone_show('179.0.0.10.in-addr.arpa.', version='2.235') 2020-06-17T10:11:24Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:24Z DEBUG raw: dnszone_show('0.0.10.in-addr.arpa.', version='2.235') 2020-06-17T10:11:24Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:24Z DEBUG raw: dnszone_show('0.10.in-addr.arpa.', version='2.235') 2020-06-17T10:11:24Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:24Z DEBUG raw: dnszone_show('10.in-addr.arpa.', version='2.235') 2020-06-17T10:11:24Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:24Z DEBUG raw: dnszone_show('in-addr.arpa.', version='2.235') 2020-06-17T10:11:24Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:24Z DEBUG raw: dnszone_show('arpa.', version='2.235') 2020-06-17T10:11:24Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:24Z DEBUG step duration: named __add_self 0.03 sec 2020-06-17T10:11:24Z DEBUG [5/11]: setting up records for other masters 2020-06-17T10:11:24Z DEBUG step duration: named __add_others 0.00 sec 2020-06-17T10:11:24Z DEBUG [6/11]: adding NS record to the zones 2020-06-17T10:11:24Z DEBUG raw: dnszone_find(None, version='2.235') 2020-06-17T10:11:24Z DEBUG dnszone_find(None, forward_only=False, all=False, raw=False, version='2.235', pkey_only=False) 2020-06-17T10:11:24Z DEBUG adding self NS to zone lin.test.lan. apex 2020-06-17T10:11:24Z DEBUG raw: dnsrecord_add('lin.test.lan.', '@', nsrecord='freeipaserver.lin.test.lan.', force=True, version='2.235') 2020-06-17T10:11:24Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, nsrecord=('freeipaserver.lin.test.lan.',), force=True, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:24Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:24Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:24Z DEBUG step duration: named __add_self_ns 0.02 sec 2020-06-17T10:11:24Z DEBUG [7/11]: setting up kerberos principal 2020-06-17T10:11:24Z DEBUG Starting external process 2020-06-17T10:11:24Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'addprinc -randkey DNS/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-x', 'ipa-setup-override-restrictions'] 2020-06-17T10:11:24Z DEBUG Process finished, return code=0 2020-06-17T10:11:24Z DEBUG stdout=Authenticating as principal root/admin@LIN.TEST.LAN with password. Principal "DNS/freeipaserver.lin.test.lan@LIN.TEST.LAN" created. 2020-06-17T10:11:24Z DEBUG stderr=WARNING: no policy specified for DNS/freeipaserver.lin.test.lan@LIN.TEST.LAN; defaulting to no policy 2020-06-17T10:11:24Z DEBUG Backing up system configuration file '/etc/named.keytab' 2020-06-17T10:11:24Z DEBUG -> Not backing up - '/etc/named.keytab' doesn't exist 2020-06-17T10:11:24Z DEBUG Starting external process 2020-06-17T10:11:24Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'ktadd -k /etc/named.keytab DNS/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-x', 'ipa-setup-override-restrictions'] 2020-06-17T10:11:24Z DEBUG Process finished, return code=0 2020-06-17T10:11:24Z DEBUG stdout=Authenticating as principal root/admin@LIN.TEST.LAN with password. Entry for principal DNS/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/named.keytab. Entry for principal DNS/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/named.keytab. Entry for principal DNS/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type aes128-cts-hmac-sha256-128 added to keytab WRFILE:/etc/named.keytab. Entry for principal DNS/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type aes256-cts-hmac-sha384-192 added to keytab WRFILE:/etc/named.keytab. Entry for principal DNS/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/named.keytab. Entry for principal DNS/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/named.keytab. 2020-06-17T10:11:24Z DEBUG stderr= 2020-06-17T10:11:24Z DEBUG step duration: named __setup_principal 0.35 sec 2020-06-17T10:11:24Z DEBUG [8/11]: setting up named.conf 2020-06-17T10:11:24Z DEBUG Backing up system configuration file '/etc/named.conf' 2020-06-17T10:11:24Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:11:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:11:24Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:11:24Z DEBUG step duration: named __setup_named_conf 0.00 sec 2020-06-17T10:11:24Z DEBUG [9/11]: setting up server configuration 2020-06-17T10:11:24Z DEBUG cn=servers,cn=dns container already exists 2020-06-17T10:11:24Z DEBUG raw: dnsserver_add('freeipaserver.lin.test.lan', idnssoamname=, version='2.235') 2020-06-17T10:11:24Z DEBUG dnsserver_add('freeipaserver.lin.test.lan', idnssoamname=, all=False, raw=False, version='2.235') 2020-06-17T10:11:24Z DEBUG raw: dnsserver_mod('freeipaserver.lin.test.lan', idnsforwarders=['10.0.0.1'], idnsforwardpolicy='only', version='2.235') 2020-06-17T10:11:24Z DEBUG dnsserver_mod('freeipaserver.lin.test.lan', idnsforwarders=('10.0.0.1',), idnsforwardpolicy='only', rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:11:24Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-17T10:11:24Z DEBUG step duration: named __setup_server_configuration 0.02 sec 2020-06-17T10:11:24Z DEBUG [10/11]: configuring named to start on boot 2020-06-17T10:11:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:24Z DEBUG Starting external process 2020-06-17T10:11:24Z DEBUG args=['/bin/systemctl', 'is-active', 'named-pkcs11.service'] 2020-06-17T10:11:24Z DEBUG Process finished, return code=3 2020-06-17T10:11:24Z DEBUG stdout=inactive 2020-06-17T10:11:24Z DEBUG stderr= 2020-06-17T10:11:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:24Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:24Z DEBUG Starting external process 2020-06-17T10:11:24Z DEBUG args=['/bin/systemctl', 'is-active', 'named.service'] 2020-06-17T10:11:24Z DEBUG Process finished, return code=3 2020-06-17T10:11:24Z DEBUG stdout=inactive 2020-06-17T10:11:24Z DEBUG stderr= 2020-06-17T10:11:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:24Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:24Z DEBUG Starting external process 2020-06-17T10:11:24Z DEBUG args=['/bin/systemctl', 'disable', 'named-pkcs11.service'] 2020-06-17T10:11:24Z DEBUG Process finished, return code=0 2020-06-17T10:11:24Z DEBUG stdout= 2020-06-17T10:11:24Z DEBUG stderr= 2020-06-17T10:11:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:24Z DEBUG Starting external process 2020-06-17T10:11:24Z DEBUG args=['/bin/systemctl', 'is-active', 'named.service'] 2020-06-17T10:11:24Z DEBUG Process finished, return code=3 2020-06-17T10:11:24Z DEBUG stdout=inactive 2020-06-17T10:11:24Z DEBUG stderr= 2020-06-17T10:11:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:24Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:24Z DEBUG Starting external process 2020-06-17T10:11:24Z DEBUG args=['/bin/systemctl', 'stop', 'named.service'] 2020-06-17T10:11:24Z DEBUG Process finished, return code=0 2020-06-17T10:11:24Z DEBUG stdout= 2020-06-17T10:11:24Z DEBUG stderr= 2020-06-17T10:11:24Z DEBUG Stop of named.service complete 2020-06-17T10:11:24Z DEBUG Starting external process 2020-06-17T10:11:24Z DEBUG args=['/bin/systemctl', 'mask', 'named.service'] 2020-06-17T10:11:24Z DEBUG Process finished, return code=0 2020-06-17T10:11:24Z DEBUG stdout= 2020-06-17T10:11:24Z DEBUG stderr=Created symlink /etc/systemd/system/named.service → /dev/null. 2020-06-17T10:11:24Z DEBUG step duration: named __enable 0.47 sec 2020-06-17T10:11:24Z DEBUG [11/11]: changing resolv.conf to point to ourselves 2020-06-17T10:11:24Z DEBUG Backing up system configuration file '/etc/resolv.conf' 2020-06-17T10:11:24Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:11:24Z DEBUG Starting external process 2020-06-17T10:11:24Z DEBUG args=['/bin/systemctl', 'is-enabled', 'NetworkManager.service'] 2020-06-17T10:11:24Z DEBUG Process finished, return code=0 2020-06-17T10:11:24Z DEBUG stdout=enabled 2020-06-17T10:11:24Z DEBUG stderr= 2020-06-17T10:11:24Z DEBUG Network Manager is enabled, write /etc/NetworkManager/conf.d/zzz-ipa.conf 2020-06-17T10:11:24Z DEBUG Starting external process 2020-06-17T10:11:24Z DEBUG args=['/bin/systemctl', 'reload-or-restart', 'NetworkManager.service'] 2020-06-17T10:11:24Z DEBUG Process finished, return code=0 2020-06-17T10:11:24Z DEBUG stdout= 2020-06-17T10:11:24Z DEBUG stderr= 2020-06-17T10:11:24Z DEBUG Starting external process 2020-06-17T10:11:24Z DEBUG args=['/bin/systemctl', 'is-active', 'NetworkManager.service'] 2020-06-17T10:11:24Z DEBUG Process finished, return code=0 2020-06-17T10:11:24Z DEBUG stdout=active 2020-06-17T10:11:24Z DEBUG stderr= 2020-06-17T10:11:24Z DEBUG Restart of NetworkManager.service complete 2020-06-17T10:11:24Z DEBUG step duration: named __setup_resolv_conf 0.08 sec 2020-06-17T10:11:24Z DEBUG Done configuring DNS (named). 2020-06-17T10:11:24Z DEBUG service duration: named 2.54 sec 2020-06-17T10:11:24Z DEBUG Starting external process 2020-06-17T10:11:24Z DEBUG args=['/bin/systemctl', 'restart', 'httpd.service'] 2020-06-17T10:11:27Z DEBUG Process finished, return code=0 2020-06-17T10:11:27Z DEBUG stdout= 2020-06-17T10:11:27Z DEBUG stderr= 2020-06-17T10:11:27Z DEBUG Starting external process 2020-06-17T10:11:27Z DEBUG args=['/bin/systemctl', 'is-active', 'httpd.service'] 2020-06-17T10:11:27Z DEBUG Process finished, return code=0 2020-06-17T10:11:27Z DEBUG stdout=reloading 2020-06-17T10:11:27Z DEBUG stderr= 2020-06-17T10:11:27Z DEBUG Restart of httpd.service complete 2020-06-17T10:11:27Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:27Z DEBUG Starting external process 2020-06-17T10:11:27Z DEBUG args=['/bin/systemctl', 'stop', 'ipa-dnskeysyncd.service'] 2020-06-17T10:11:27Z DEBUG Process finished, return code=0 2020-06-17T10:11:27Z DEBUG stdout= 2020-06-17T10:11:27Z DEBUG stderr= 2020-06-17T10:11:27Z DEBUG Stop of ipa-dnskeysyncd.service complete 2020-06-17T10:11:27Z DEBUG Configuring DNS key synchronization service (ipa-dnskeysyncd) 2020-06-17T10:11:27Z DEBUG [1/7]: checking status 2020-06-17T10:11:27Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:27Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:27Z DEBUG step duration: ipa-dnskeysyncd __check_dnssec_status 0.00 sec 2020-06-17T10:11:27Z DEBUG [2/7]: setting up bind-dyndb-ldap working directory 2020-06-17T10:11:27Z DEBUG step duration: ipa-dnskeysyncd set_dyndb_ldap_workdir_permissions 0.00 sec 2020-06-17T10:11:27Z DEBUG [3/7]: setting up kerberos principal 2020-06-17T10:11:27Z DEBUG Removing service keytab: /etc/ipa/dnssec/ipa-dnskeysyncd.keytab 2020-06-17T10:11:27Z DEBUG Starting external process 2020-06-17T10:11:27Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'addprinc -randkey ipa-dnskeysyncd/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-x', 'ipa-setup-override-restrictions'] 2020-06-17T10:11:28Z DEBUG Process finished, return code=0 2020-06-17T10:11:28Z DEBUG stdout=Authenticating as principal root/admin@LIN.TEST.LAN with password. Principal "ipa-dnskeysyncd/freeipaserver.lin.test.lan@LIN.TEST.LAN" created. 2020-06-17T10:11:28Z DEBUG stderr=WARNING: no policy specified for ipa-dnskeysyncd/freeipaserver.lin.test.lan@LIN.TEST.LAN; defaulting to no policy 2020-06-17T10:11:28Z DEBUG Starting external process 2020-06-17T10:11:28Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'ktadd -k /etc/ipa/dnssec/ipa-dnskeysyncd.keytab ipa-dnskeysyncd/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-x', 'ipa-setup-override-restrictions'] 2020-06-17T10:11:29Z DEBUG Process finished, return code=0 2020-06-17T10:11:29Z DEBUG stdout=Authenticating as principal root/admin@LIN.TEST.LAN with password. Entry for principal ipa-dnskeysyncd/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. Entry for principal ipa-dnskeysyncd/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. Entry for principal ipa-dnskeysyncd/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type aes128-cts-hmac-sha256-128 added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. Entry for principal ipa-dnskeysyncd/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type aes256-cts-hmac-sha384-192 added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. Entry for principal ipa-dnskeysyncd/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. Entry for principal ipa-dnskeysyncd/freeipaserver.lin.test.lan@LIN.TEST.LAN with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. 2020-06-17T10:11:29Z DEBUG stderr= 2020-06-17T10:11:29Z DEBUG step duration: ipa-dnskeysyncd __setup_principal 2.37 sec 2020-06-17T10:11:29Z DEBUG [4/7]: setting up SoftHSM 2020-06-17T10:11:29Z DEBUG Creating /var/lib/ipa/dnssec directory 2020-06-17T10:11:29Z DEBUG Creating new softhsm config file 2020-06-17T10:11:29Z DEBUG Backing up system configuration file '/etc/sysconfig/named' 2020-06-17T10:11:29Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:11:29Z DEBUG Creating tokens /var/lib/ipa/dnssec/tokens directory 2020-06-17T10:11:29Z DEBUG Saving user PIN to /var/lib/ipa/dnssec/softhsm_pin 2020-06-17T10:11:29Z DEBUG Saving SO PIN to /etc/ipa/dnssec/softhsm_pin_so 2020-06-17T10:11:29Z DEBUG Initializing tokens 2020-06-17T10:11:29Z DEBUG Starting external process 2020-06-17T10:11:29Z DEBUG args=['/usr/bin/softhsm2-util', '--init-token', '--free', '--label', 'ipaDNSSEC', '--pin', XXXXXXXX, '--so-pin', XXXXXXXX] 2020-06-17T10:11:30Z DEBUG Process finished, return code=0 2020-06-17T10:11:30Z DEBUG stdout=Slot 0 has a free/uninitialized token. The token has been initialized and is reassigned to slot 1589408666 2020-06-17T10:11:30Z DEBUG stderr= 2020-06-17T10:11:30Z DEBUG step duration: ipa-dnskeysyncd __setup_softhsm 0.15 sec 2020-06-17T10:11:30Z DEBUG [5/7]: adding DNSSEC containers 2020-06-17T10:11:30Z DEBUG Starting external process 2020-06-17T10:11:30Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpuqq67yla', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:11:30Z DEBUG Process finished, return code=0 2020-06-17T10:11:30Z DEBUG stdout=add objectClass: nsContainer top add cn: sec adding new entry "cn=sec,cn=dns,dc=lin,dc=test,dc=lan" modify complete add objectClass: nsContainer top add cn: keys adding new entry "cn=keys,cn=sec,cn=dns,dc=lin,dc=test,dc=lan" modify complete 2020-06-17T10:11:30Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:11:30Z DEBUG step duration: ipa-dnskeysyncd __setup_dnssec_containers 0.16 sec 2020-06-17T10:11:30Z DEBUG [6/7]: creating replica keys 2020-06-17T10:11:30Z DEBUG Creating replica's key pair 2020-06-17T10:11:31Z DEBUG Storing replica public key to LDAP, ipk11UniqueId=autogenerate,cn=keys,cn=sec,cn=dns,dc=lin,dc=test,dc=lan 2020-06-17T10:11:31Z DEBUG Replica public key stored 2020-06-17T10:11:31Z DEBUG Setting CKA_WRAP=False for old replica keys 2020-06-17T10:11:32Z DEBUG Changing ownership of token files 2020-06-17T10:11:32Z DEBUG step duration: ipa-dnskeysyncd __setup_replica_keys 1.77 sec 2020-06-17T10:11:32Z DEBUG [7/7]: configuring ipa-dnskeysyncd to start on boot 2020-06-17T10:11:32Z DEBUG Starting external process 2020-06-17T10:11:32Z DEBUG args=['/bin/systemctl', 'disable', 'ipa-dnskeysyncd.service'] 2020-06-17T10:11:32Z DEBUG Process finished, return code=0 2020-06-17T10:11:32Z DEBUG stdout= 2020-06-17T10:11:32Z DEBUG stderr= 2020-06-17T10:11:32Z DEBUG step duration: ipa-dnskeysyncd __enable 0.75 sec 2020-06-17T10:11:32Z DEBUG Done configuring DNS key synchronization service (ipa-dnskeysyncd). 2020-06-17T10:11:32Z DEBUG service duration: ipa-dnskeysyncd 5.20 sec 2020-06-17T10:11:32Z DEBUG Starting external process 2020-06-17T10:11:32Z DEBUG args=['/bin/systemctl', 'restart', 'ipa-dnskeysyncd.service'] 2020-06-17T10:11:32Z DEBUG Process finished, return code=0 2020-06-17T10:11:32Z DEBUG stdout= 2020-06-17T10:11:32Z DEBUG stderr= 2020-06-17T10:11:32Z DEBUG Starting external process 2020-06-17T10:11:32Z DEBUG args=['/bin/systemctl', 'is-active', 'ipa-dnskeysyncd.service'] 2020-06-17T10:11:32Z DEBUG Process finished, return code=0 2020-06-17T10:11:32Z DEBUG stdout=active 2020-06-17T10:11:32Z DEBUG stderr= 2020-06-17T10:11:32Z DEBUG Restart of ipa-dnskeysyncd.service complete 2020-06-17T10:11:32Z DEBUG Restarting named 2020-06-17T10:11:32Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:32Z DEBUG Starting external process 2020-06-17T10:11:32Z DEBUG args=['/bin/systemctl', 'is-active', 'named-pkcs11.service'] 2020-06-17T10:11:33Z DEBUG Process finished, return code=3 2020-06-17T10:11:33Z DEBUG stdout=inactive 2020-06-17T10:11:33Z DEBUG stderr= 2020-06-17T10:11:33Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:33Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:11:33Z DEBUG Starting external process 2020-06-17T10:11:33Z DEBUG args=['/bin/systemctl', 'restart', 'named-pkcs11.service'] 2020-06-17T10:11:34Z DEBUG Process finished, return code=0 2020-06-17T10:11:34Z DEBUG stdout= 2020-06-17T10:11:34Z DEBUG stderr= 2020-06-17T10:11:34Z DEBUG Starting external process 2020-06-17T10:11:34Z DEBUG args=['/bin/systemctl', 'is-active', 'named-pkcs11.service'] 2020-06-17T10:11:34Z DEBUG Process finished, return code=0 2020-06-17T10:11:34Z DEBUG stdout=active 2020-06-17T10:11:34Z DEBUG stderr= 2020-06-17T10:11:34Z DEBUG Restart of named-pkcs11.service complete 2020-06-17T10:11:34Z DEBUG Updating DNS system records 2020-06-17T10:11:34Z DEBUG raw: server_find(None, version='2.235', no_members=False, servrole='IPA master') 2020-06-17T10:11:34Z DEBUG server_find(None, all=False, raw=False, version='2.235', no_members=False, pkey_only=False, servrole=('IPA master',)) 2020-06-17T10:11:34Z DEBUG raw: server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, version='2.235') 2020-06-17T10:11:34Z DEBUG server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T10:11:34Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version='2.235') 2020-06-17T10:11:34Z DEBUG topologysuffix_find(None, all=True, raw=True, version='2.235', pkey_only=False) 2020-06-17T10:11:34Z DEBUG raw: dnszone_show(, version='2.235') 2020-06-17T10:11:34Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:34Z DEBUG raw: location_find(None, version='2.235') 2020-06-17T10:11:34Z DEBUG location_find(None, all=False, raw=False, version='2.235', pkey_only=False) 2020-06-17T10:11:34Z DEBUG Changing admin password 2020-06-17T10:11:34Z DEBUG Starting external process 2020-06-17T10:11:34Z DEBUG args=['/usr/bin/ldappasswd', '-h', 'freeipaserver.lin.test.lan', '-ZZ', '-x', '-D', 'cn=Directory Manager', '-y', '/var/lib/ipa/tmpowtmrb0n', '-T', '/var/lib/ipa/tmph684g_79', 'uid=admin,cn=users,cn=accounts,dc=lin,dc=test,dc=lan'] 2020-06-17T10:11:35Z DEBUG Process finished, return code=0 2020-06-17T10:11:35Z DEBUG stdout= 2020-06-17T10:11:35Z DEBUG stderr= 2020-06-17T10:11:35Z DEBUG ldappasswd done 2020-06-17T10:11:35Z DEBUG Configuring client side components 2020-06-17T10:11:35Z DEBUG Starting external process 2020-06-17T10:11:35Z DEBUG args=['/usr/sbin/ipa-client-install', '--on-master', '--unattended', '--domain', 'lin.test.lan', '--server', 'freeipaserver.lin.test.lan', '--realm', 'LIN.TEST.LAN', '--hostname', 'freeipaserver.lin.test.lan', '--no-ntp', '--mkhomedir'] 2020-06-17T10:11:51Z DEBUG Process finished, return code=0 2020-06-17T10:11:51Z DEBUG Client install duration: 15.894 2020-06-17T10:11:51Z DEBUG Set service ['KDC'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T10:11:51Z DEBUG Set service ['KPASSWD'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T10:11:51Z DEBUG Set service ['KEYS'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T10:11:51Z DEBUG Set service ['CA'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T10:11:51Z DEBUG Set service ['OTPD'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T10:11:51Z DEBUG Set service ['HTTP'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T10:11:51Z DEBUG Set service ['DNS'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T10:11:51Z DEBUG Set service ['DNSKeySync'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T10:11:51Z DEBUG raw: dns_update_system_records(version='2.235') 2020-06-17T10:11:51Z DEBUG dns_update_system_records(dry_run=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: server_find(None, version='2.235', no_members=False, servrole='IPA master') 2020-06-17T10:11:51Z DEBUG server_find(None, all=False, raw=False, version='2.235', no_members=False, pkey_only=False, servrole=('IPA master',)) 2020-06-17T10:11:51Z DEBUG raw: server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, version='2.235') 2020-06-17T10:11:51Z DEBUG server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version='2.235') 2020-06-17T10:11:51Z DEBUG topologysuffix_find(None, all=True, raw=True, version='2.235', pkey_only=False) 2020-06-17T10:11:51Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, version='2.235') 2020-06-17T10:11:51Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnszone_show(, version='2.235') 2020-06-17T10:11:51Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG found 1 1 records for freeipaserver.lin.test.lan.: 10.0.0.179 2020-06-17T10:11:51Z DEBUG The DNS response does not contain an answer to the question: freeipaserver.lin.test.lan. IN AAAA 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_mod(, , txtrecord=['"LIN.TEST.LAN"'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_mod(, , txtrecord=('"LIN.TEST.LAN"',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), force=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), force=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), force=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), force=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), force=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), force=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), force=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_mod(, , arecord=['10.0.0.179'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_mod(, , arecord=('10.0.0.179',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: dnsrecord_add(, , arecord=['10.0.0.179'], version='2.235') 2020-06-17T10:11:51Z DEBUG dnsrecord_add(, , arecord=('10.0.0.179',), a_extra_create_reverse=False, aaaa_extra_create_reverse=False, force=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:11:51Z DEBUG raw: location_find(None, version='2.235') 2020-06-17T10:11:51Z DEBUG location_find(None, all=False, raw=False, version='2.235', pkey_only=False) 2020-06-17T10:11:51Z DEBUG Starting external process 2020-06-17T10:11:51Z DEBUG args=['/bin/systemctl', 'enable', 'ipa.service'] 2020-06-17T10:11:51Z DEBUG Process finished, return code=0 2020-06-17T10:11:51Z DEBUG stdout= 2020-06-17T10:11:51Z DEBUG stderr=Created symlink /etc/systemd/system/multi-user.target.wants/ipa.service → /usr/lib/systemd/system/ipa.service. 2020-06-17T10:11:51Z DEBUG Starting external process 2020-06-17T10:11:51Z DEBUG args=['/bin/systemctl', 'restart', 'ipa.service'] 2020-06-17T10:11:54Z DEBUG Process finished, return code=0 2020-06-17T10:11:54Z DEBUG stdout= 2020-06-17T10:11:54Z DEBUG stderr= 2020-06-17T10:11:54Z DEBUG Starting external process 2020-06-17T10:11:54Z DEBUG args=['/bin/systemctl', 'is-active', 'ipa.service'] 2020-06-17T10:11:54Z DEBUG Process finished, return code=0 2020-06-17T10:11:54Z DEBUG stdout=active 2020-06-17T10:11:54Z DEBUG stderr= 2020-06-17T10:11:54Z DEBUG Restart of ipa.service complete 2020-06-17T10:11:54Z DEBUG Starting external process 2020-06-17T10:11:54Z DEBUG args=['/bin/systemctl', 'is-active', 'chronyd.service'] 2020-06-17T10:11:54Z DEBUG Process finished, return code=0 2020-06-17T10:11:54Z DEBUG stdout=active 2020-06-17T10:11:54Z DEBUG stderr= 2020-06-17T10:11:54Z INFO The ipa-server-install command was successful 2020-06-17T10:14:43Z DEBUG /usr/sbin/ipa-adtrust-install was invoked with options: {'debug': False, 'netbios_name': 'LIN', 'no_msdcs': False, 'rid_base': 1000, 'secondary_rid_base': 100000000, 'unattended': True, 'add_sids': True, 'add_agents': False, 'enable_compat': False} 2020-06-17T10:14:43Z DEBUG missing options might be asked for interactively later 2020-06-17T10:14:43Z DEBUG IPA version 4.8.4-7.module_el8.2.0+374+0d2d74a1 2020-06-17T10:14:43Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:14:43Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:14:43Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.aci 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.automember 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.automount 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-06-17T10:14:43Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.batch 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.ca 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.cert 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.config 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.dns 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.group 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-06-17T10:14:43Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.host 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.idoverride-admemberof 2020-06-17T10:14:43Z DEBUG ipaserver.plugins.idoverride-admemberof is not a valid plugin module 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.internal 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.join 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.location 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.migration 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.misc 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.otp 2020-06-17T10:14:43Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.permission 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.ping 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-06-17T10:14:43Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.role 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.schema 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-06-17T10:14:43Z DEBUG importing plugin module ipaserver.plugins.server 2020-06-17T10:14:44Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-06-17T10:14:44Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-06-17T10:14:44Z DEBUG importing plugin module ipaserver.plugins.service 2020-06-17T10:14:44Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-06-17T10:14:44Z DEBUG importing plugin module ipaserver.plugins.session 2020-06-17T10:14:44Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-06-17T10:14:44Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-06-17T10:14:44Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-06-17T10:14:44Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-06-17T10:14:44Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-06-17T10:14:44Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-06-17T10:14:44Z DEBUG importing plugin module ipaserver.plugins.topology 2020-06-17T10:14:44Z DEBUG importing plugin module ipaserver.plugins.trust 2020-06-17T10:14:44Z DEBUG importing plugin module ipaserver.plugins.user 2020-06-17T10:14:44Z DEBUG importing plugin module ipaserver.plugins.vault 2020-06-17T10:14:44Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-06-17T10:14:44Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-06-17T10:14:44Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-06-17T10:14:44Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-06-17T10:14:45Z DEBUG Starting external process 2020-06-17T10:14:45Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T10:14:45Z DEBUG Process finished, return code=0 2020-06-17T10:14:45Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T10:14:45Z DEBUG stderr= 2020-06-17T10:14:45Z DEBUG Created connection context.ldap2_140145257700152 2020-06-17T10:14:46Z DEBUG raw: user_show('admin', version='2.235') 2020-06-17T10:14:46Z DEBUG user_show('admin', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T10:14:46Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:14:46Z DEBUG raw: group_show('admins', version='2.235') 2020-06-17T10:14:46Z DEBUG group_show('admins', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T10:14:46Z DEBUG No previous trust configuration found 2020-06-17T10:14:46Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:14:46Z DEBUG Configuring CIFS 2020-06-17T10:14:46Z DEBUG [1/24]: validate server hostname 2020-06-17T10:14:46Z DEBUG step duration: smb __validate_server_hostname 0.00 sec 2020-06-17T10:14:46Z DEBUG [2/24]: stopping smbd 2020-06-17T10:14:46Z DEBUG Starting external process 2020-06-17T10:14:46Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T10:14:46Z DEBUG Process finished, return code=0 2020-06-17T10:14:46Z DEBUG stdout=active 2020-06-17T10:14:46Z DEBUG stderr= 2020-06-17T10:14:46Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:14:46Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:14:46Z DEBUG Starting external process 2020-06-17T10:14:46Z DEBUG args=['/bin/systemctl', 'stop', 'winbind.service'] 2020-06-17T10:14:46Z DEBUG Process finished, return code=0 2020-06-17T10:14:46Z DEBUG stdout= 2020-06-17T10:14:46Z DEBUG stderr= 2020-06-17T10:14:46Z DEBUG Stop of winbind.service complete 2020-06-17T10:14:46Z DEBUG Starting external process 2020-06-17T10:14:46Z DEBUG args=['/bin/systemctl', 'stop', 'smb.service'] 2020-06-17T10:14:46Z DEBUG Process finished, return code=0 2020-06-17T10:14:46Z DEBUG stdout= 2020-06-17T10:14:46Z DEBUG stderr= 2020-06-17T10:14:46Z DEBUG Stop of smb.service complete 2020-06-17T10:14:46Z DEBUG step duration: smb __stop 0.05 sec 2020-06-17T10:14:46Z DEBUG [3/24]: creating samba domain object 2020-06-17T10:14:46Z DEBUG step duration: smb __create_samba_domain_object 0.04 sec 2020-06-17T10:14:46Z DEBUG [4/24]: retrieve local idmap range 2020-06-17T10:14:46Z DEBUG raw: idrange_show('LIN.TEST.LAN_id_range', version='2.235') 2020-06-17T10:14:46Z DEBUG idrange_show('LIN.TEST.LAN_id_range', rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:46Z DEBUG step duration: smb __retrieve_local_range 0.00 sec 2020-06-17T10:14:46Z DEBUG [5/24]: creating samba config registry 2020-06-17T10:14:46Z DEBUG Starting external process 2020-06-17T10:14:46Z DEBUG args=['/usr/bin/net', 'conf', 'import', '/tmp/tmp8wf3lkcx'] 2020-06-17T10:14:46Z DEBUG Process finished, return code=0 2020-06-17T10:14:46Z DEBUG stdout= 2020-06-17T10:14:46Z DEBUG stderr= 2020-06-17T10:14:46Z DEBUG step duration: smb __write_smb_registry 0.10 sec 2020-06-17T10:14:46Z DEBUG [6/24]: writing samba config file 2020-06-17T10:14:46Z DEBUG step duration: smb __write_smb_conf 0.00 sec 2020-06-17T10:14:46Z DEBUG [7/24]: adding cifs Kerberos principal 2020-06-17T10:14:46Z DEBUG raw: service_add('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', force=True, version='2.235') 2020-06-17T10:14:46Z DEBUG service_add(ipapython.kerberos.Principal('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN'), force=True, skip_host_check=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T10:14:46Z DEBUG raw: host_show('freeipaserver.lin.test.lan', version='2.235') 2020-06-17T10:14:46Z DEBUG host_show('freeipaserver.lin.test.lan', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T10:14:46Z DEBUG Removing service credentials cache 2020-06-17T10:14:46Z DEBUG Ccache path: '/var/run/samba/krb5cc_samba' 2020-06-17T10:14:46Z DEBUG Starting external process 2020-06-17T10:14:46Z DEBUG args=['/usr/bin/kdestroy', '-c', '/var/run/samba/krb5cc_samba'] 2020-06-17T10:14:46Z DEBUG Process finished, return code=0 2020-06-17T10:14:46Z DEBUG stdout= 2020-06-17T10:14:46Z DEBUG stderr=kdestroy: No credentials cache found while destroying cache 2020-06-17T10:14:46Z DEBUG Starting external process 2020-06-17T10:14:46Z DEBUG args=['/usr/sbin/ipa-getkeytab', '-k', '/etc/samba/samba.keytab', '-p', 'cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:14:46Z DEBUG Process finished, return code=0 2020-06-17T10:14:46Z DEBUG stdout= 2020-06-17T10:14:46Z DEBUG stderr=Récupération du tableau de clés et stockage avec succès dans : /etc/samba/samba.keytab 2020-06-17T10:14:46Z DEBUG step duration: smb request_service_keytab 0.08 sec 2020-06-17T10:14:46Z DEBUG [8/24]: adding cifs and host Kerberos principals to the adtrust agents group 2020-06-17T10:14:46Z DEBUG step duration: smb __setup_group_membership 0.03 sec 2020-06-17T10:14:46Z DEBUG [9/24]: check for cifs services defined on other replicas 2020-06-17T10:14:46Z DEBUG step duration: smb __check_replica 0.00 sec 2020-06-17T10:14:46Z DEBUG [10/24]: adding cifs principal to S4U2Proxy targets 2020-06-17T10:14:46Z DEBUG step duration: smb __add_s4u2proxy_target 0.01 sec 2020-06-17T10:14:46Z DEBUG [11/24]: adding admin(group) SIDs 2020-06-17T10:14:46Z DEBUG step duration: smb __add_admin_sids 0.02 sec 2020-06-17T10:14:46Z DEBUG [12/24]: adding RID bases 2020-06-17T10:14:46Z DEBUG step duration: smb __add_rid_bases 0.00 sec 2020-06-17T10:14:46Z DEBUG [13/24]: updating Kerberos config 2020-06-17T10:14:46Z DEBUG 'dns_lookup_kdc' already set to 'true', nothing to do. 2020-06-17T10:14:46Z DEBUG step duration: smb __update_krb5_conf 0.00 sec 2020-06-17T10:14:46Z DEBUG [14/24]: activating CLDAP plugin 2020-06-17T10:14:46Z DEBUG Starting external process 2020-06-17T10:14:46Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp5v48tuok', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:14:46Z DEBUG Process finished, return code=0 2020-06-17T10:14:46Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa_cldap add nsslapd-pluginpath: libipa_cldap add nsslapd-plugininitfunc: ipa_cldap_init add nsslapd-plugintype: postoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_cldap_init add nsslapd-pluginversion: @PACKAGE_VERSION@ add nsslapd-pluginvendor: RedHat add nsslapd-plugindescription: CLDAP Server to interoperate with AD add nsslapd-plugin-depends-on-type: database add nsslapd-basedn: dc=lin,dc=test,dc=lan adding new entry "cn=ipa_cldap,cn=plugins,cn=config" modify complete 2020-06-17T10:14:46Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:14:46Z DEBUG step duration: smb __add_cldap_module 0.03 sec 2020-06-17T10:14:46Z DEBUG [15/24]: activating sidgen task 2020-06-17T10:14:46Z DEBUG Starting external process 2020-06-17T10:14:46Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpm37z9tuq', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:14:46Z DEBUG Process finished, return code=0 2020-06-17T10:14:46Z DEBUG stdout=add objectClass: top nsSlapdPlugin extensibleObject add cn: ipa-sidgen-task add nsslapd-pluginPath: libipa_sidgen_task add nsslapd-pluginInitfunc: sidgen_task_init add nsslapd-pluginType: object add nsslapd-pluginEnabled: on add nsslapd-pluginId: ipa_sidgen_task add nsslapd-pluginVersion: 1.0 add nsslapd-pluginVendor: RedHat add nsslapd-pluginDescription: Generate SIDs for existing user and group entries adding new entry "cn=ipa-sidgen-task,cn=plugins,cn=config" modify complete add objectClass: top extensibleObject add cn: ipa-sidgen-task adding new entry "cn=ipa-sidgen-task,cn=tasks,cn=config" modify complete 2020-06-17T10:14:46Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:14:46Z DEBUG step duration: smb __add_sidgen_task 0.03 sec 2020-06-17T10:14:46Z DEBUG [16/24]: map BUILTIN\Guests to nobody group 2020-06-17T10:14:46Z DEBUG Map BUILTIN\Guests to a group 'nobody' 2020-06-17T10:14:46Z DEBUG Starting external process 2020-06-17T10:14:46Z DEBUG args=['/usr/bin/net', '-s', '/dev/null', 'groupmap', 'add', 'sid=S-1-5-32-546', 'unixgroup=nobody', 'type=builtin'] 2020-06-17T10:14:46Z DEBUG Process finished, return code=0 2020-06-17T10:14:46Z DEBUG stdout=Successfully added group nobody to the mapping db as a wellknown group 2020-06-17T10:14:46Z DEBUG stderr= 2020-06-17T10:14:46Z DEBUG step duration: smb __map_Guests_to_nobody 0.10 sec 2020-06-17T10:14:46Z DEBUG [17/24]: configuring smbd to start on boot 2020-06-17T10:14:46Z DEBUG Starting external process 2020-06-17T10:14:46Z DEBUG args=['/bin/systemctl', 'is-enabled', 'smb.service'] 2020-06-17T10:14:46Z DEBUG Process finished, return code=0 2020-06-17T10:14:46Z DEBUG stdout=enabled 2020-06-17T10:14:46Z DEBUG stderr= 2020-06-17T10:14:46Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:14:46Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:14:46Z DEBUG Starting external process 2020-06-17T10:14:46Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T10:14:46Z DEBUG Process finished, return code=0 2020-06-17T10:14:46Z DEBUG stdout= 2020-06-17T10:14:46Z DEBUG stderr=Removed /etc/systemd/system/multi-user.target.wants/smb.service. 2020-06-17T10:14:46Z DEBUG Starting external process 2020-06-17T10:14:46Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T10:14:47Z DEBUG Process finished, return code=0 2020-06-17T10:14:47Z DEBUG stdout= 2020-06-17T10:14:47Z DEBUG stderr= 2020-06-17T10:14:47Z DEBUG step duration: smb __enable 0.42 sec 2020-06-17T10:14:47Z DEBUG [18/24]: restarting Directory Server to take MS PAC and LDAP plugins changes into account 2020-06-17T10:14:47Z DEBUG Destroyed connection context.ldap2_140145257700152 2020-06-17T10:14:47Z DEBUG Starting external process 2020-06-17T10:14:47Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:14:51Z DEBUG Process finished, return code=0 2020-06-17T10:14:51Z DEBUG stdout= 2020-06-17T10:14:51Z DEBUG stderr= 2020-06-17T10:14:51Z DEBUG Restart of dirsrv@LIN-TEST-LAN.service complete 2020-06-17T10:14:51Z DEBUG Created connection context.ldap2_140145257700152 2020-06-17T10:14:51Z DEBUG step duration: smb __restart_dirsrv 4.75 sec 2020-06-17T10:14:51Z DEBUG [19/24]: adding fallback group 2020-06-17T10:14:51Z DEBUG Starting external process 2020-06-17T10:14:51Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpzymrcoxi', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:14:51Z DEBUG Process finished, return code=0 2020-06-17T10:14:51Z DEBUG stdout=add cn: Default SMB Group add description: Fallback group for primary group RID, do not add users to this group add gidnumber: -1 add objectclass: top ipaobject posixgroup adding new entry "cn=Default SMB Group,cn=groups,cn=accounts,dc=lin,dc=test,dc=lan" modify complete 2020-06-17T10:14:51Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:14:51Z DEBUG step duration: smb __add_fallback_group 0.08 sec 2020-06-17T10:14:51Z DEBUG [20/24]: adding Default Trust View 2020-06-17T10:14:51Z DEBUG Starting external process 2020-06-17T10:14:51Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp20ztjbtm', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:14:51Z DEBUG Process finished, return code=0 2020-06-17T10:14:51Z DEBUG stdout=add cn: Default Trust View add description: Default Trust View for AD users. Should not be deleted. add objectclass: top ipaIDView adding new entry "cn=Default Trust View,cn=views,cn=accounts,dc=lin,dc=test,dc=lan" modify complete 2020-06-17T10:14:51Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:14:51Z DEBUG step duration: smb __add_default_trust_view 0.02 sec 2020-06-17T10:14:51Z DEBUG [21/24]: setting SELinux booleans 2020-06-17T10:14:51Z DEBUG Starting external process 2020-06-17T10:14:51Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T10:14:51Z DEBUG Process finished, return code=0 2020-06-17T10:14:51Z DEBUG stdout= 2020-06-17T10:14:51Z DEBUG stderr= 2020-06-17T10:14:51Z DEBUG Starting external process 2020-06-17T10:14:51Z DEBUG args=['/usr/sbin/getsebool', 'samba_portmapper'] 2020-06-17T10:14:51Z DEBUG Process finished, return code=0 2020-06-17T10:14:51Z DEBUG stdout=samba_portmapper --> off 2020-06-17T10:14:51Z DEBUG stderr= 2020-06-17T10:14:51Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:14:51Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:14:51Z DEBUG Starting external process 2020-06-17T10:14:51Z DEBUG args=['/usr/sbin/setsebool', '-P', 'samba_portmapper=on'] 2020-06-17T10:14:55Z DEBUG Process finished, return code=0 2020-06-17T10:14:55Z DEBUG stdout= 2020-06-17T10:14:55Z DEBUG stderr= 2020-06-17T10:14:55Z DEBUG step duration: smb __configure_selinux_for_smbd 3.24 sec 2020-06-17T10:14:55Z DEBUG [22/24]: starting CIFS services 2020-06-17T10:14:55Z DEBUG Starting external process 2020-06-17T10:14:55Z DEBUG args=['/bin/systemctl', 'start', 'smb.service'] 2020-06-17T10:14:55Z DEBUG Process finished, return code=0 2020-06-17T10:14:55Z DEBUG stdout= 2020-06-17T10:14:55Z DEBUG stderr= 2020-06-17T10:14:55Z DEBUG Starting external process 2020-06-17T10:14:55Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T10:14:55Z DEBUG Process finished, return code=0 2020-06-17T10:14:55Z DEBUG stdout=active 2020-06-17T10:14:55Z DEBUG stderr= 2020-06-17T10:14:55Z DEBUG Start of smb.service complete 2020-06-17T10:14:55Z DEBUG Starting external process 2020-06-17T10:14:55Z DEBUG args=['/bin/systemctl', 'start', 'winbind.service'] 2020-06-17T10:14:55Z DEBUG Process finished, return code=0 2020-06-17T10:14:55Z DEBUG stdout= 2020-06-17T10:14:55Z DEBUG stderr= 2020-06-17T10:14:55Z DEBUG Starting external process 2020-06-17T10:14:55Z DEBUG args=['/bin/systemctl', 'is-active', 'winbind.service'] 2020-06-17T10:14:55Z DEBUG Process finished, return code=0 2020-06-17T10:14:55Z DEBUG stdout=active 2020-06-17T10:14:55Z DEBUG stderr= 2020-06-17T10:14:55Z DEBUG Start of winbind.service complete 2020-06-17T10:14:55Z DEBUG step duration: smb __start 0.61 sec 2020-06-17T10:14:55Z DEBUG [23/24]: adding SIDs to existing users and groups 2020-06-17T10:14:55Z DEBUG Starting external process 2020-06-17T10:14:55Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp6k9r0pr7', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:14:55Z DEBUG Process finished, return code=0 2020-06-17T10:14:55Z DEBUG stdout=add objectClass: top extensibleObject add cn: sidgen add nsslapd-basedn: dc=lin,dc=test,dc=lan add delay: 0 adding new entry "cn=sidgen,cn=ipa-sidgen-task,cn=tasks,cn=config" modify complete 2020-06-17T10:14:55Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:14:55Z DEBUG This step may take considerable amount of time, please wait.. 2020-06-17T10:14:56Z DEBUG step duration: smb __add_sids 1.02 sec 2020-06-17T10:14:56Z DEBUG [24/24]: restarting smbd 2020-06-17T10:14:56Z DEBUG step duration: smb __restart_smb 0.00 sec 2020-06-17T10:14:56Z DEBUG Done configuring CIFS. 2020-06-17T10:14:56Z DEBUG service duration: smb 10.65 sec 2020-06-17T10:14:56Z DEBUG raw: update_host_cifs_keytabs 2020-06-17T10:14:56Z DEBUG raw: adtrust_is_enabled(version='2.235') 2020-06-17T10:14:56Z DEBUG adtrust_is_enabled(version='2.235') 2020-06-17T10:14:56Z DEBUG Starting external process 2020-06-17T10:14:56Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/krb5.keytab'] 2020-06-17T10:14:56Z DEBUG Process finished, return code=0 2020-06-17T10:14:56Z DEBUG stdout= 2020-06-17T10:14:56Z DEBUG stderr= 2020-06-17T10:14:56Z DEBUG Starting external process 2020-06-17T10:14:56Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/samba/samba.keytab'] 2020-06-17T10:14:56Z DEBUG Process finished, return code=0 2020-06-17T10:14:56Z DEBUG stdout= 2020-06-17T10:14:56Z DEBUG stderr= 2020-06-17T10:14:56Z DEBUG Starting external process 2020-06-17T10:14:56Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T10:14:56Z DEBUG Process finished, return code=0 2020-06-17T10:14:56Z DEBUG stdout= 2020-06-17T10:14:56Z DEBUG stderr= 2020-06-17T10:14:56Z DEBUG Starting external process 2020-06-17T10:14:56Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T10:14:56Z DEBUG Process finished, return code=0 2020-06-17T10:14:56Z DEBUG stdout= 2020-06-17T10:14:56Z DEBUG stderr= 2020-06-17T10:14:56Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', version='2.235') 2020-06-17T10:14:56Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', include_master=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:56Z DEBUG Set service ['ADTRUST'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T10:14:56Z DEBUG Set service ['EXTID'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T10:14:56Z DEBUG raw: dns_is_enabled(version='2.235') 2020-06-17T10:14:56Z DEBUG dns_is_enabled(version='2.235') 2020-06-17T10:14:56Z DEBUG raw: dnszone_show('lin.test.lan', version='2.235') 2020-06-17T10:14:56Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:56Z DEBUG raw: dns_update_system_records(version='2.235') 2020-06-17T10:14:56Z DEBUG dns_update_system_records(dry_run=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:56Z DEBUG raw: server_find(None, version='2.235', no_members=False, servrole='IPA master') 2020-06-17T10:14:56Z DEBUG server_find(None, all=False, raw=False, version='2.235', no_members=False, pkey_only=False, servrole=('IPA master',)) 2020-06-17T10:14:56Z DEBUG raw: server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, version='2.235') 2020-06-17T10:14:56Z DEBUG server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T10:14:56Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version='2.235') 2020-06-17T10:14:56Z DEBUG topologysuffix_find(None, all=True, raw=True, version='2.235', pkey_only=False) 2020-06-17T10:14:56Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, version='2.235') 2020-06-17T10:14:56Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T10:14:56Z DEBUG raw: dnszone_show(, version='2.235') 2020-06-17T10:14:56Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:56Z DEBUG found 1 1 records for freeipaserver.lin.test.lan.: 10.0.0.179 2020-06-17T10:14:56Z DEBUG The DNS response does not contain an answer to the question: freeipaserver.lin.test.lan. IN AAAA 2020-06-17T10:14:56Z DEBUG raw: dnsrecord_mod(, , txtrecord=['"LIN.TEST.LAN"'], version='2.235') 2020-06-17T10:14:56Z DEBUG dnsrecord_mod(, , txtrecord=('"LIN.TEST.LAN"',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:56Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:14:56Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:56Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:14:56Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:56Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:14:56Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:56Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:14:56Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:56Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:14:56Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:14:57Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:14:57Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: dnsrecord_mod(, , arecord=['10.0.0.179'], version='2.235') 2020-06-17T10:14:57Z DEBUG dnsrecord_mod(, , arecord=('10.0.0.179',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:14:57Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], version='2.235') 2020-06-17T10:14:57Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), force=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:14:57Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:14:57Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], version='2.235') 2020-06-17T10:14:57Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), force=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:14:57Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:14:57Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], version='2.235') 2020-06-17T10:14:57Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), force=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:14:57Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:14:57Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], version='2.235') 2020-06-17T10:14:57Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), force=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:14:57Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:14:57Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], version='2.235') 2020-06-17T10:14:57Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), force=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:14:57Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:14:57Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], version='2.235') 2020-06-17T10:14:57Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), force=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:14:57Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:14:57Z DEBUG raw: location_find(None, version='2.235') 2020-06-17T10:14:57Z DEBUG location_find(None, all=False, raw=False, version='2.235', pkey_only=False) 2020-06-17T10:14:57Z DEBUG Starting external process 2020-06-17T10:14:57Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T10:14:57Z DEBUG Process finished, return code=0 2020-06-17T10:14:57Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T10:14:57Z DEBUG stderr= 2020-06-17T10:14:57Z DEBUG Destroyed connection context.ldap2_140145257700152 2020-06-17T10:14:57Z INFO The ipa-adtrust-install command was successful 2020-06-17T10:21:59Z DEBUG /usr/sbin/ipa-adtrust-install was invoked with options: {'debug': False, 'netbios_name': 'LIN', 'no_msdcs': False, 'rid_base': 1000, 'secondary_rid_base': 100000000, 'unattended': True, 'add_sids': True, 'add_agents': False, 'enable_compat': False} 2020-06-17T10:21:59Z DEBUG missing options might be asked for interactively later 2020-06-17T10:21:59Z DEBUG IPA version 4.8.4-7.module_el8.2.0+374+0d2d74a1 2020-06-17T10:21:59Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:21:59Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:21:59Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.aci 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.automember 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.automount 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-06-17T10:21:59Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.batch 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.ca 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.cert 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.config 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.dns 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.group 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-06-17T10:21:59Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.host 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.idoverride-admemberof 2020-06-17T10:21:59Z DEBUG ipaserver.plugins.idoverride-admemberof is not a valid plugin module 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.internal 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.join 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.location 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.migration 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.misc 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.otp 2020-06-17T10:21:59Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.permission 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.ping 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-06-17T10:21:59Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.role 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.schema 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.server 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.service 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.session 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-06-17T10:21:59Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.topology 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.trust 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.user 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.vault 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-06-17T10:21:59Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-06-17T10:21:59Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-06-17T10:22:00Z DEBUG Starting external process 2020-06-17T10:22:00Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T10:22:01Z DEBUG Process finished, return code=0 2020-06-17T10:22:01Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T10:22:01Z DEBUG stderr= 2020-06-17T10:22:01Z DEBUG Created connection context.ldap2_139761751857976 2020-06-17T10:22:01Z DEBUG raw: user_show('admin', version='2.235') 2020-06-17T10:22:01Z DEBUG user_show('admin', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T10:22:01Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:22:01Z DEBUG raw: group_show('admins', version='2.235') 2020-06-17T10:22:01Z DEBUG group_show('admins', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T10:22:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:22:01Z DEBUG Configuring CIFS 2020-06-17T10:22:01Z DEBUG [1/24]: validate server hostname 2020-06-17T10:22:01Z DEBUG step duration: smb __validate_server_hostname 0.00 sec 2020-06-17T10:22:01Z DEBUG [2/24]: stopping smbd 2020-06-17T10:22:01Z DEBUG Starting external process 2020-06-17T10:22:01Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T10:22:01Z DEBUG Process finished, return code=0 2020-06-17T10:22:01Z DEBUG stdout=active 2020-06-17T10:22:01Z DEBUG stderr= 2020-06-17T10:22:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:22:01Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:22:01Z DEBUG Starting external process 2020-06-17T10:22:01Z DEBUG args=['/bin/systemctl', 'stop', 'winbind.service'] 2020-06-17T10:22:01Z DEBUG Process finished, return code=0 2020-06-17T10:22:01Z DEBUG stdout= 2020-06-17T10:22:01Z DEBUG stderr= 2020-06-17T10:22:01Z DEBUG Stop of winbind.service complete 2020-06-17T10:22:01Z DEBUG Starting external process 2020-06-17T10:22:01Z DEBUG args=['/bin/systemctl', 'stop', 'smb.service'] 2020-06-17T10:22:01Z DEBUG Process finished, return code=0 2020-06-17T10:22:01Z DEBUG stdout= 2020-06-17T10:22:01Z DEBUG stderr= 2020-06-17T10:22:01Z DEBUG Stop of smb.service complete 2020-06-17T10:22:01Z DEBUG step duration: smb __stop 0.06 sec 2020-06-17T10:22:01Z DEBUG [3/24]: creating samba domain object 2020-06-17T10:22:01Z DEBUG Samba domain object already exists 2020-06-17T10:22:01Z DEBUG step duration: smb __create_samba_domain_object 0.00 sec 2020-06-17T10:22:01Z DEBUG [4/24]: retrieve local idmap range 2020-06-17T10:22:01Z DEBUG raw: idrange_show('LIN.TEST.LAN_id_range', version='2.235') 2020-06-17T10:22:01Z DEBUG idrange_show('LIN.TEST.LAN_id_range', rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:22:01Z DEBUG step duration: smb __retrieve_local_range 0.00 sec 2020-06-17T10:22:01Z DEBUG [5/24]: creating samba config registry 2020-06-17T10:22:01Z DEBUG Starting external process 2020-06-17T10:22:01Z DEBUG args=['/usr/bin/net', 'conf', 'import', '/tmp/tmplc88d532'] 2020-06-17T10:22:01Z DEBUG Process finished, return code=0 2020-06-17T10:22:01Z DEBUG stdout= 2020-06-17T10:22:01Z DEBUG stderr= 2020-06-17T10:22:01Z DEBUG step duration: smb __write_smb_registry 0.10 sec 2020-06-17T10:22:01Z DEBUG [6/24]: writing samba config file 2020-06-17T10:22:01Z DEBUG step duration: smb __write_smb_conf 0.00 sec 2020-06-17T10:22:01Z DEBUG [7/24]: adding cifs Kerberos principal 2020-06-17T10:22:01Z DEBUG raw: service_add('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', force=True, version='2.235') 2020-06-17T10:22:01Z DEBUG service_add(ipapython.kerberos.Principal('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN'), force=True, skip_host_check=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T10:22:01Z DEBUG raw: host_show('freeipaserver.lin.test.lan', version='2.235') 2020-06-17T10:22:01Z DEBUG host_show('freeipaserver.lin.test.lan', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T10:22:01Z DEBUG Starting external process 2020-06-17T10:22:01Z DEBUG args=['/usr/sbin/ipa-rmkeytab', '--principal', 'cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-k', '/etc/samba/samba.keytab'] 2020-06-17T10:22:01Z DEBUG Process finished, return code=0 2020-06-17T10:22:01Z DEBUG stdout= 2020-06-17T10:22:01Z DEBUG stderr=Suppression du principal cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN 2020-06-17T10:22:01Z DEBUG Removing service credentials cache 2020-06-17T10:22:01Z DEBUG Ccache path: '/var/run/samba/krb5cc_samba' 2020-06-17T10:22:01Z DEBUG Starting external process 2020-06-17T10:22:01Z DEBUG args=['/usr/bin/kdestroy', '-c', '/var/run/samba/krb5cc_samba'] 2020-06-17T10:22:01Z DEBUG Process finished, return code=0 2020-06-17T10:22:01Z DEBUG stdout= 2020-06-17T10:22:01Z DEBUG stderr= 2020-06-17T10:22:01Z DEBUG Starting external process 2020-06-17T10:22:01Z DEBUG args=['/usr/sbin/ipa-getkeytab', '-k', '/etc/samba/samba.keytab', '-p', 'cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:22:01Z DEBUG Process finished, return code=0 2020-06-17T10:22:01Z DEBUG stdout= 2020-06-17T10:22:01Z DEBUG stderr=Récupération du tableau de clés et stockage avec succès dans : /etc/samba/samba.keytab 2020-06-17T10:22:01Z DEBUG step duration: smb request_service_keytab 0.07 sec 2020-06-17T10:22:01Z DEBUG [8/24]: adding cifs and host Kerberos principals to the adtrust agents group 2020-06-17T10:22:01Z DEBUG step duration: smb __setup_group_membership 0.00 sec 2020-06-17T10:22:01Z DEBUG [9/24]: check for cifs services defined on other replicas 2020-06-17T10:22:01Z DEBUG step duration: smb __check_replica 0.00 sec 2020-06-17T10:22:01Z DEBUG [10/24]: adding cifs principal to S4U2Proxy targets 2020-06-17T10:22:01Z DEBUG cifs principal already targeted, nothing to do. 2020-06-17T10:22:01Z DEBUG step duration: smb __add_s4u2proxy_target 0.00 sec 2020-06-17T10:22:01Z DEBUG [11/24]: adding admin(group) SIDs 2020-06-17T10:22:01Z DEBUG Admin SID already set, nothing to do 2020-06-17T10:22:01Z DEBUG Admin group SID already set, nothing to do 2020-06-17T10:22:01Z DEBUG step duration: smb __add_admin_sids 0.00 sec 2020-06-17T10:22:01Z DEBUG [12/24]: adding RID bases 2020-06-17T10:22:01Z DEBUG RID bases already set, nothing to do 2020-06-17T10:22:01Z DEBUG step duration: smb __add_rid_bases 0.00 sec 2020-06-17T10:22:01Z DEBUG [13/24]: updating Kerberos config 2020-06-17T10:22:01Z DEBUG 'dns_lookup_kdc' already set to 'true', nothing to do. 2020-06-17T10:22:01Z DEBUG step duration: smb __update_krb5_conf 0.00 sec 2020-06-17T10:22:01Z DEBUG [14/24]: activating CLDAP plugin 2020-06-17T10:22:01Z DEBUG CLDAP plugin already configured, nothing to do 2020-06-17T10:22:01Z DEBUG step duration: smb __add_cldap_module 0.00 sec 2020-06-17T10:22:01Z DEBUG [15/24]: activating sidgen task 2020-06-17T10:22:01Z DEBUG Sidgen task plugin already configured, nothing to do 2020-06-17T10:22:01Z DEBUG step duration: smb __add_sidgen_task 0.00 sec 2020-06-17T10:22:01Z DEBUG [16/24]: map BUILTIN\Guests to nobody group 2020-06-17T10:22:01Z DEBUG Map BUILTIN\Guests to a group 'nobody' 2020-06-17T10:22:01Z DEBUG Starting external process 2020-06-17T10:22:01Z DEBUG args=['/usr/bin/net', '-s', '/dev/null', 'groupmap', 'add', 'sid=S-1-5-32-546', 'unixgroup=nobody', 'type=builtin'] 2020-06-17T10:22:01Z DEBUG Process finished, return code=255 2020-06-17T10:22:01Z DEBUG stdout=Unix group nobody already mapped to SID S-1-5-32-546 2020-06-17T10:22:01Z DEBUG stderr= 2020-06-17T10:22:01Z DEBUG step duration: smb __map_Guests_to_nobody 0.08 sec 2020-06-17T10:22:01Z DEBUG [17/24]: configuring smbd to start on boot 2020-06-17T10:22:01Z DEBUG Starting external process 2020-06-17T10:22:01Z DEBUG args=['/bin/systemctl', 'is-enabled', 'smb.service'] 2020-06-17T10:22:01Z DEBUG Process finished, return code=0 2020-06-17T10:22:01Z DEBUG stdout=enabled 2020-06-17T10:22:01Z DEBUG stderr= 2020-06-17T10:22:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:22:01Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:22:01Z DEBUG Starting external process 2020-06-17T10:22:01Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T10:22:01Z DEBUG Process finished, return code=0 2020-06-17T10:22:01Z DEBUG stdout= 2020-06-17T10:22:01Z DEBUG stderr=Removed /etc/systemd/system/multi-user.target.wants/smb.service. 2020-06-17T10:22:01Z DEBUG service ADTRUST has all config values set 2020-06-17T10:22:01Z DEBUG Starting external process 2020-06-17T10:22:01Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T10:22:02Z DEBUG Process finished, return code=0 2020-06-17T10:22:02Z DEBUG stdout= 2020-06-17T10:22:02Z DEBUG stderr= 2020-06-17T10:22:02Z DEBUG service EXTID has all config values set 2020-06-17T10:22:02Z DEBUG step duration: smb __enable 0.43 sec 2020-06-17T10:22:02Z DEBUG [18/24]: restarting Directory Server to take MS PAC and LDAP plugins changes into account 2020-06-17T10:22:02Z DEBUG Destroyed connection context.ldap2_139761751857976 2020-06-17T10:22:02Z DEBUG Starting external process 2020-06-17T10:22:02Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:22:07Z DEBUG Process finished, return code=0 2020-06-17T10:22:07Z DEBUG stdout= 2020-06-17T10:22:07Z DEBUG stderr= 2020-06-17T10:22:07Z DEBUG Restart of dirsrv@LIN-TEST-LAN.service complete 2020-06-17T10:22:07Z DEBUG Created connection context.ldap2_139761751857976 2020-06-17T10:22:07Z DEBUG step duration: smb __restart_dirsrv 4.98 sec 2020-06-17T10:22:07Z DEBUG [19/24]: adding fallback group 2020-06-17T10:22:07Z DEBUG Fallback group already set, nothing to do 2020-06-17T10:22:07Z DEBUG step duration: smb __add_fallback_group 0.00 sec 2020-06-17T10:22:07Z DEBUG [20/24]: adding Default Trust View 2020-06-17T10:22:07Z DEBUG Default Trust View already exists. 2020-06-17T10:22:07Z DEBUG step duration: smb __add_default_trust_view 0.00 sec 2020-06-17T10:22:07Z DEBUG [21/24]: setting SELinux booleans 2020-06-17T10:22:07Z DEBUG Starting external process 2020-06-17T10:22:07Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T10:22:07Z DEBUG Process finished, return code=0 2020-06-17T10:22:07Z DEBUG stdout= 2020-06-17T10:22:07Z DEBUG stderr= 2020-06-17T10:22:07Z DEBUG Starting external process 2020-06-17T10:22:07Z DEBUG args=['/usr/sbin/getsebool', 'samba_portmapper'] 2020-06-17T10:22:07Z DEBUG Process finished, return code=0 2020-06-17T10:22:07Z DEBUG stdout=samba_portmapper --> on 2020-06-17T10:22:07Z DEBUG stderr= 2020-06-17T10:22:07Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:22:07Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:22:07Z DEBUG step duration: smb __configure_selinux_for_smbd 0.02 sec 2020-06-17T10:22:07Z DEBUG [22/24]: starting CIFS services 2020-06-17T10:22:07Z DEBUG Starting external process 2020-06-17T10:22:07Z DEBUG args=['/bin/systemctl', 'start', 'smb.service'] 2020-06-17T10:22:07Z DEBUG Process finished, return code=0 2020-06-17T10:22:07Z DEBUG stdout= 2020-06-17T10:22:07Z DEBUG stderr= 2020-06-17T10:22:07Z DEBUG Starting external process 2020-06-17T10:22:07Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T10:22:07Z DEBUG Process finished, return code=0 2020-06-17T10:22:07Z DEBUG stdout=active 2020-06-17T10:22:07Z DEBUG stderr= 2020-06-17T10:22:07Z DEBUG Start of smb.service complete 2020-06-17T10:22:07Z DEBUG Starting external process 2020-06-17T10:22:07Z DEBUG args=['/bin/systemctl', 'start', 'winbind.service'] 2020-06-17T10:22:07Z DEBUG Process finished, return code=0 2020-06-17T10:22:07Z DEBUG stdout= 2020-06-17T10:22:07Z DEBUG stderr= 2020-06-17T10:22:07Z DEBUG Starting external process 2020-06-17T10:22:07Z DEBUG args=['/bin/systemctl', 'is-active', 'winbind.service'] 2020-06-17T10:22:07Z DEBUG Process finished, return code=0 2020-06-17T10:22:07Z DEBUG stdout=active 2020-06-17T10:22:07Z DEBUG stderr= 2020-06-17T10:22:07Z DEBUG Start of winbind.service complete 2020-06-17T10:22:07Z DEBUG step duration: smb __start 0.80 sec 2020-06-17T10:22:07Z DEBUG [23/24]: adding SIDs to existing users and groups 2020-06-17T10:22:07Z DEBUG Starting external process 2020-06-17T10:22:07Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp7vrq3uhn', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:22:07Z DEBUG Process finished, return code=0 2020-06-17T10:22:07Z DEBUG stdout=add objectClass: top extensibleObject add cn: sidgen add nsslapd-basedn: dc=lin,dc=test,dc=lan add delay: 0 adding new entry "cn=sidgen,cn=ipa-sidgen-task,cn=tasks,cn=config" modify complete 2020-06-17T10:22:07Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:22:07Z DEBUG This step may take considerable amount of time, please wait.. 2020-06-17T10:22:08Z DEBUG step duration: smb __add_sids 1.02 sec 2020-06-17T10:22:08Z DEBUG [24/24]: restarting smbd 2020-06-17T10:22:08Z DEBUG step duration: smb __restart_smb 0.00 sec 2020-06-17T10:22:08Z DEBUG Done configuring CIFS. 2020-06-17T10:22:08Z DEBUG service duration: smb 7.59 sec 2020-06-17T10:22:08Z DEBUG raw: update_host_cifs_keytabs 2020-06-17T10:22:08Z DEBUG raw: adtrust_is_enabled(version='2.235') 2020-06-17T10:22:08Z DEBUG adtrust_is_enabled(version='2.235') 2020-06-17T10:22:08Z DEBUG Starting external process 2020-06-17T10:22:08Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/krb5.keytab'] 2020-06-17T10:22:08Z DEBUG Process finished, return code=0 2020-06-17T10:22:08Z DEBUG stdout= 2020-06-17T10:22:08Z DEBUG stderr= 2020-06-17T10:22:08Z DEBUG Starting external process 2020-06-17T10:22:08Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/samba/samba.keytab'] 2020-06-17T10:22:08Z DEBUG Process finished, return code=0 2020-06-17T10:22:08Z DEBUG stdout= 2020-06-17T10:22:08Z DEBUG stderr= 2020-06-17T10:22:08Z DEBUG Starting external process 2020-06-17T10:22:08Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T10:22:08Z DEBUG Process finished, return code=0 2020-06-17T10:22:08Z DEBUG stdout= 2020-06-17T10:22:08Z DEBUG stderr= 2020-06-17T10:22:08Z DEBUG Starting external process 2020-06-17T10:22:08Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T10:22:08Z DEBUG Process finished, return code=0 2020-06-17T10:22:08Z DEBUG stdout= 2020-06-17T10:22:08Z DEBUG stderr= 2020-06-17T10:22:08Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', version='2.235') 2020-06-17T10:22:08Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', include_master=False, all=False, raw=False, version='2.235') 2020-06-17T10:22:08Z DEBUG Set service ['ADTRUST'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T10:22:08Z DEBUG Set service ['EXTID'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T10:22:08Z DEBUG raw: dns_is_enabled(version='2.235') 2020-06-17T10:22:08Z DEBUG dns_is_enabled(version='2.235') 2020-06-17T10:22:08Z DEBUG raw: dnszone_show('lin.test.lan', version='2.235') 2020-06-17T10:22:08Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:22:08Z DEBUG raw: dns_update_system_records(version='2.235') 2020-06-17T10:22:08Z DEBUG dns_update_system_records(dry_run=False, all=False, raw=False, version='2.235') 2020-06-17T10:22:08Z DEBUG raw: server_find(None, version='2.235', no_members=False, servrole='IPA master') 2020-06-17T10:22:08Z DEBUG server_find(None, all=False, raw=False, version='2.235', no_members=False, pkey_only=False, servrole=('IPA master',)) 2020-06-17T10:22:08Z DEBUG raw: server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, version='2.235') 2020-06-17T10:22:08Z DEBUG server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T10:22:08Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version='2.235') 2020-06-17T10:22:08Z DEBUG topologysuffix_find(None, all=True, raw=True, version='2.235', pkey_only=False) 2020-06-17T10:22:08Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, version='2.235') 2020-06-17T10:22:08Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T10:22:08Z DEBUG raw: dnszone_show(, version='2.235') 2020-06-17T10:22:08Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:22:08Z DEBUG found 1 1 records for freeipaserver.lin.test.lan.: 10.0.0.179 2020-06-17T10:22:08Z DEBUG The DNS response does not contain an answer to the question: freeipaserver.lin.test.lan. IN AAAA 2020-06-17T10:22:08Z DEBUG raw: dnsrecord_mod(, , txtrecord=['"LIN.TEST.LAN"'], version='2.235') 2020-06-17T10:22:08Z DEBUG dnsrecord_mod(, , txtrecord=('"LIN.TEST.LAN"',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:22:08Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:22:08Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:22:08Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:22:08Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:22:09Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:22:09Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:22:09Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:22:09Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:22:09Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:22:09Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:22:09Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:22:09Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:22:09Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:22:09Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:22:09Z DEBUG raw: dnsrecord_mod(, , arecord=['10.0.0.179'], version='2.235') 2020-06-17T10:22:09Z DEBUG dnsrecord_mod(, , arecord=('10.0.0.179',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:22:09Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:22:09Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:22:09Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:22:09Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:22:09Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:22:09Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:22:09Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:22:09Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:22:09Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:22:09Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:22:09Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:22:09Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:22:09Z DEBUG raw: location_find(None, version='2.235') 2020-06-17T10:22:09Z DEBUG location_find(None, all=False, raw=False, version='2.235', pkey_only=False) 2020-06-17T10:22:09Z DEBUG Starting external process 2020-06-17T10:22:09Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T10:22:09Z DEBUG Process finished, return code=0 2020-06-17T10:22:09Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T10:22:09Z DEBUG stderr= 2020-06-17T10:22:09Z DEBUG Destroyed connection context.ldap2_139761751857976 2020-06-17T10:22:09Z INFO The ipa-adtrust-install command was successful 2020-06-17T10:25:45Z DEBUG /usr/sbin/ipa-adtrust-install was invoked with options: {'debug': False, 'netbios_name': 'LIN', 'no_msdcs': False, 'rid_base': 1000, 'secondary_rid_base': 100000000, 'unattended': True, 'add_sids': True, 'add_agents': False, 'enable_compat': False} 2020-06-17T10:25:45Z DEBUG missing options might be asked for interactively later 2020-06-17T10:25:45Z DEBUG IPA version 4.8.4-7.module_el8.2.0+374+0d2d74a1 2020-06-17T10:25:45Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:25:45Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:25:45Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.aci 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.automember 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.automount 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-06-17T10:25:45Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.batch 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.ca 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.cert 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.config 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.dns 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.group 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-06-17T10:25:45Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.host 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.idoverride-admemberof 2020-06-17T10:25:45Z DEBUG ipaserver.plugins.idoverride-admemberof is not a valid plugin module 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.internal 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.join 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.location 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.migration 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.misc 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.otp 2020-06-17T10:25:45Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.permission 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.ping 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-06-17T10:25:45Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.role 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.schema 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-06-17T10:25:45Z DEBUG importing plugin module ipaserver.plugins.server 2020-06-17T10:25:46Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-06-17T10:25:46Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-06-17T10:25:46Z DEBUG importing plugin module ipaserver.plugins.service 2020-06-17T10:25:46Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-06-17T10:25:46Z DEBUG importing plugin module ipaserver.plugins.session 2020-06-17T10:25:46Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-06-17T10:25:46Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-06-17T10:25:46Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-06-17T10:25:46Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-06-17T10:25:46Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-06-17T10:25:46Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-06-17T10:25:46Z DEBUG importing plugin module ipaserver.plugins.topology 2020-06-17T10:25:46Z DEBUG importing plugin module ipaserver.plugins.trust 2020-06-17T10:25:46Z DEBUG importing plugin module ipaserver.plugins.user 2020-06-17T10:25:46Z DEBUG importing plugin module ipaserver.plugins.vault 2020-06-17T10:25:46Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-06-17T10:25:46Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-06-17T10:25:46Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-06-17T10:25:46Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-06-17T10:25:47Z DEBUG Starting external process 2020-06-17T10:25:47Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T10:25:47Z DEBUG Process finished, return code=0 2020-06-17T10:25:47Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T10:25:47Z DEBUG stderr= 2020-06-17T10:25:47Z DEBUG Created connection context.ldap2_139859026836392 2020-06-17T10:25:47Z DEBUG raw: user_show('admin', version='2.235') 2020-06-17T10:25:47Z DEBUG user_show('admin', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T10:25:47Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:25:47Z DEBUG raw: group_show('admins', version='2.235') 2020-06-17T10:25:47Z DEBUG group_show('admins', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T10:25:47Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:25:47Z DEBUG Configuring CIFS 2020-06-17T10:25:47Z DEBUG [1/24]: validate server hostname 2020-06-17T10:25:47Z DEBUG step duration: smb __validate_server_hostname 0.00 sec 2020-06-17T10:25:47Z DEBUG [2/24]: stopping smbd 2020-06-17T10:25:47Z DEBUG Starting external process 2020-06-17T10:25:47Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T10:25:47Z DEBUG Process finished, return code=0 2020-06-17T10:25:47Z DEBUG stdout=active 2020-06-17T10:25:47Z DEBUG stderr= 2020-06-17T10:25:47Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:25:47Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:25:47Z DEBUG Starting external process 2020-06-17T10:25:47Z DEBUG args=['/bin/systemctl', 'stop', 'winbind.service'] 2020-06-17T10:25:47Z DEBUG Process finished, return code=0 2020-06-17T10:25:47Z DEBUG stdout= 2020-06-17T10:25:47Z DEBUG stderr= 2020-06-17T10:25:47Z DEBUG Stop of winbind.service complete 2020-06-17T10:25:47Z DEBUG Starting external process 2020-06-17T10:25:47Z DEBUG args=['/bin/systemctl', 'stop', 'smb.service'] 2020-06-17T10:25:47Z DEBUG Process finished, return code=0 2020-06-17T10:25:47Z DEBUG stdout= 2020-06-17T10:25:47Z DEBUG stderr= 2020-06-17T10:25:47Z DEBUG Stop of smb.service complete 2020-06-17T10:25:47Z DEBUG step duration: smb __stop 0.09 sec 2020-06-17T10:25:47Z DEBUG [3/24]: creating samba domain object 2020-06-17T10:25:47Z DEBUG Samba domain object already exists 2020-06-17T10:25:47Z DEBUG step duration: smb __create_samba_domain_object 0.00 sec 2020-06-17T10:25:47Z DEBUG [4/24]: retrieve local idmap range 2020-06-17T10:25:47Z DEBUG raw: idrange_show('LIN.TEST.LAN_id_range', version='2.235') 2020-06-17T10:25:47Z DEBUG idrange_show('LIN.TEST.LAN_id_range', rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:25:47Z DEBUG step duration: smb __retrieve_local_range 0.00 sec 2020-06-17T10:25:47Z DEBUG [5/24]: creating samba config registry 2020-06-17T10:25:47Z DEBUG Starting external process 2020-06-17T10:25:47Z DEBUG args=['/usr/bin/net', 'conf', 'import', '/tmp/tmpa8vpeako'] 2020-06-17T10:25:47Z DEBUG Process finished, return code=0 2020-06-17T10:25:47Z DEBUG stdout= 2020-06-17T10:25:47Z DEBUG stderr= 2020-06-17T10:25:47Z DEBUG step duration: smb __write_smb_registry 0.09 sec 2020-06-17T10:25:47Z DEBUG [6/24]: writing samba config file 2020-06-17T10:25:47Z DEBUG step duration: smb __write_smb_conf 0.00 sec 2020-06-17T10:25:47Z DEBUG [7/24]: adding cifs Kerberos principal 2020-06-17T10:25:47Z DEBUG raw: service_add('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', force=True, version='2.235') 2020-06-17T10:25:47Z DEBUG service_add(ipapython.kerberos.Principal('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN'), force=True, skip_host_check=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T10:25:47Z DEBUG raw: host_show('freeipaserver.lin.test.lan', version='2.235') 2020-06-17T10:25:47Z DEBUG host_show('freeipaserver.lin.test.lan', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T10:25:47Z DEBUG Starting external process 2020-06-17T10:25:47Z DEBUG args=['/usr/sbin/ipa-rmkeytab', '--principal', 'cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-k', '/etc/samba/samba.keytab'] 2020-06-17T10:25:47Z DEBUG Process finished, return code=0 2020-06-17T10:25:47Z DEBUG stdout= 2020-06-17T10:25:47Z DEBUG stderr=Suppression du principal cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN 2020-06-17T10:25:47Z DEBUG Removing service credentials cache 2020-06-17T10:25:47Z DEBUG Ccache path: '/var/run/samba/krb5cc_samba' 2020-06-17T10:25:47Z DEBUG Starting external process 2020-06-17T10:25:47Z DEBUG args=['/usr/bin/kdestroy', '-c', '/var/run/samba/krb5cc_samba'] 2020-06-17T10:25:47Z DEBUG Process finished, return code=0 2020-06-17T10:25:47Z DEBUG stdout= 2020-06-17T10:25:47Z DEBUG stderr= 2020-06-17T10:25:47Z DEBUG Starting external process 2020-06-17T10:25:47Z DEBUG args=['/usr/sbin/ipa-getkeytab', '-k', '/etc/samba/samba.keytab', '-p', 'cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:25:47Z DEBUG Process finished, return code=0 2020-06-17T10:25:47Z DEBUG stdout= 2020-06-17T10:25:47Z DEBUG stderr=Récupération du tableau de clés et stockage avec succès dans : /etc/samba/samba.keytab 2020-06-17T10:25:47Z DEBUG step duration: smb request_service_keytab 0.07 sec 2020-06-17T10:25:47Z DEBUG [8/24]: adding cifs and host Kerberos principals to the adtrust agents group 2020-06-17T10:25:47Z DEBUG step duration: smb __setup_group_membership 0.00 sec 2020-06-17T10:25:47Z DEBUG [9/24]: check for cifs services defined on other replicas 2020-06-17T10:25:47Z DEBUG step duration: smb __check_replica 0.00 sec 2020-06-17T10:25:47Z DEBUG [10/24]: adding cifs principal to S4U2Proxy targets 2020-06-17T10:25:47Z DEBUG cifs principal already targeted, nothing to do. 2020-06-17T10:25:47Z DEBUG step duration: smb __add_s4u2proxy_target 0.00 sec 2020-06-17T10:25:47Z DEBUG [11/24]: adding admin(group) SIDs 2020-06-17T10:25:47Z DEBUG Admin SID already set, nothing to do 2020-06-17T10:25:47Z DEBUG Admin group SID already set, nothing to do 2020-06-17T10:25:47Z DEBUG step duration: smb __add_admin_sids 0.00 sec 2020-06-17T10:25:47Z DEBUG [12/24]: adding RID bases 2020-06-17T10:25:47Z DEBUG RID bases already set, nothing to do 2020-06-17T10:25:47Z DEBUG step duration: smb __add_rid_bases 0.00 sec 2020-06-17T10:25:47Z DEBUG [13/24]: updating Kerberos config 2020-06-17T10:25:47Z DEBUG 'dns_lookup_kdc' already set to 'true', nothing to do. 2020-06-17T10:25:47Z DEBUG step duration: smb __update_krb5_conf 0.00 sec 2020-06-17T10:25:47Z DEBUG [14/24]: activating CLDAP plugin 2020-06-17T10:25:47Z DEBUG CLDAP plugin already configured, nothing to do 2020-06-17T10:25:47Z DEBUG step duration: smb __add_cldap_module 0.00 sec 2020-06-17T10:25:47Z DEBUG [15/24]: activating sidgen task 2020-06-17T10:25:47Z DEBUG Sidgen task plugin already configured, nothing to do 2020-06-17T10:25:47Z DEBUG step duration: smb __add_sidgen_task 0.00 sec 2020-06-17T10:25:47Z DEBUG [16/24]: map BUILTIN\Guests to nobody group 2020-06-17T10:25:47Z DEBUG Map BUILTIN\Guests to a group 'nobody' 2020-06-17T10:25:47Z DEBUG Starting external process 2020-06-17T10:25:47Z DEBUG args=['/usr/bin/net', '-s', '/dev/null', 'groupmap', 'add', 'sid=S-1-5-32-546', 'unixgroup=nobody', 'type=builtin'] 2020-06-17T10:25:47Z DEBUG Process finished, return code=255 2020-06-17T10:25:47Z DEBUG stdout=Unix group nobody already mapped to SID S-1-5-32-546 2020-06-17T10:25:47Z DEBUG stderr= 2020-06-17T10:25:47Z DEBUG step duration: smb __map_Guests_to_nobody 0.07 sec 2020-06-17T10:25:47Z DEBUG [17/24]: configuring smbd to start on boot 2020-06-17T10:25:47Z DEBUG Starting external process 2020-06-17T10:25:47Z DEBUG args=['/bin/systemctl', 'is-enabled', 'smb.service'] 2020-06-17T10:25:47Z DEBUG Process finished, return code=0 2020-06-17T10:25:47Z DEBUG stdout=enabled 2020-06-17T10:25:47Z DEBUG stderr= 2020-06-17T10:25:47Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:25:47Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:25:47Z DEBUG Starting external process 2020-06-17T10:25:47Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T10:25:48Z DEBUG Process finished, return code=0 2020-06-17T10:25:48Z DEBUG stdout= 2020-06-17T10:25:48Z DEBUG stderr=Removed /etc/systemd/system/multi-user.target.wants/smb.service. 2020-06-17T10:25:48Z DEBUG service ADTRUST has all config values set 2020-06-17T10:25:48Z DEBUG Starting external process 2020-06-17T10:25:48Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T10:25:48Z DEBUG Process finished, return code=0 2020-06-17T10:25:48Z DEBUG stdout= 2020-06-17T10:25:48Z DEBUG stderr= 2020-06-17T10:25:48Z DEBUG service EXTID has all config values set 2020-06-17T10:25:48Z DEBUG step duration: smb __enable 0.39 sec 2020-06-17T10:25:48Z DEBUG [18/24]: restarting Directory Server to take MS PAC and LDAP plugins changes into account 2020-06-17T10:25:48Z DEBUG Destroyed connection context.ldap2_139859026836392 2020-06-17T10:25:48Z DEBUG Starting external process 2020-06-17T10:25:48Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:25:51Z DEBUG Process finished, return code=0 2020-06-17T10:25:51Z DEBUG stdout= 2020-06-17T10:25:51Z DEBUG stderr= 2020-06-17T10:25:51Z DEBUG Restart of dirsrv@LIN-TEST-LAN.service complete 2020-06-17T10:25:51Z DEBUG Created connection context.ldap2_139859026836392 2020-06-17T10:25:51Z DEBUG step duration: smb __restart_dirsrv 3.52 sec 2020-06-17T10:25:51Z DEBUG [19/24]: adding fallback group 2020-06-17T10:25:51Z DEBUG Fallback group already set, nothing to do 2020-06-17T10:25:51Z DEBUG step duration: smb __add_fallback_group 0.00 sec 2020-06-17T10:25:51Z DEBUG [20/24]: adding Default Trust View 2020-06-17T10:25:51Z DEBUG Default Trust View already exists. 2020-06-17T10:25:51Z DEBUG step duration: smb __add_default_trust_view 0.00 sec 2020-06-17T10:25:51Z DEBUG [21/24]: setting SELinux booleans 2020-06-17T10:25:51Z DEBUG Starting external process 2020-06-17T10:25:51Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T10:25:51Z DEBUG Process finished, return code=0 2020-06-17T10:25:51Z DEBUG stdout= 2020-06-17T10:25:51Z DEBUG stderr= 2020-06-17T10:25:51Z DEBUG Starting external process 2020-06-17T10:25:51Z DEBUG args=['/usr/sbin/getsebool', 'samba_portmapper'] 2020-06-17T10:25:51Z DEBUG Process finished, return code=0 2020-06-17T10:25:51Z DEBUG stdout=samba_portmapper --> on 2020-06-17T10:25:51Z DEBUG stderr= 2020-06-17T10:25:51Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:25:51Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:25:51Z DEBUG step duration: smb __configure_selinux_for_smbd 0.02 sec 2020-06-17T10:25:51Z DEBUG [22/24]: starting CIFS services 2020-06-17T10:25:51Z DEBUG Starting external process 2020-06-17T10:25:51Z DEBUG args=['/bin/systemctl', 'start', 'smb.service'] 2020-06-17T10:25:52Z DEBUG Process finished, return code=0 2020-06-17T10:25:52Z DEBUG stdout= 2020-06-17T10:25:52Z DEBUG stderr= 2020-06-17T10:25:52Z DEBUG Starting external process 2020-06-17T10:25:52Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T10:25:52Z DEBUG Process finished, return code=0 2020-06-17T10:25:52Z DEBUG stdout=active 2020-06-17T10:25:52Z DEBUG stderr= 2020-06-17T10:25:52Z DEBUG Start of smb.service complete 2020-06-17T10:25:52Z DEBUG Starting external process 2020-06-17T10:25:52Z DEBUG args=['/bin/systemctl', 'start', 'winbind.service'] 2020-06-17T10:25:52Z DEBUG Process finished, return code=0 2020-06-17T10:25:52Z DEBUG stdout= 2020-06-17T10:25:52Z DEBUG stderr= 2020-06-17T10:25:52Z DEBUG Starting external process 2020-06-17T10:25:52Z DEBUG args=['/bin/systemctl', 'is-active', 'winbind.service'] 2020-06-17T10:25:52Z DEBUG Process finished, return code=0 2020-06-17T10:25:52Z DEBUG stdout=active 2020-06-17T10:25:52Z DEBUG stderr= 2020-06-17T10:25:52Z DEBUG Start of winbind.service complete 2020-06-17T10:25:52Z DEBUG step duration: smb __start 0.85 sec 2020-06-17T10:25:52Z DEBUG [23/24]: adding SIDs to existing users and groups 2020-06-17T10:25:52Z DEBUG Starting external process 2020-06-17T10:25:52Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpiy8pp2bt', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:25:52Z DEBUG Process finished, return code=0 2020-06-17T10:25:52Z DEBUG stdout=add objectClass: top extensibleObject add cn: sidgen add nsslapd-basedn: dc=lin,dc=test,dc=lan add delay: 0 adding new entry "cn=sidgen,cn=ipa-sidgen-task,cn=tasks,cn=config" modify complete 2020-06-17T10:25:52Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:25:52Z DEBUG This step may take considerable amount of time, please wait.. 2020-06-17T10:25:53Z DEBUG step duration: smb __add_sids 1.05 sec 2020-06-17T10:25:53Z DEBUG [24/24]: restarting smbd 2020-06-17T10:25:53Z DEBUG step duration: smb __restart_smb 0.00 sec 2020-06-17T10:25:53Z DEBUG Done configuring CIFS. 2020-06-17T10:25:53Z DEBUG service duration: smb 6.18 sec 2020-06-17T10:25:53Z DEBUG raw: update_host_cifs_keytabs 2020-06-17T10:25:53Z DEBUG raw: adtrust_is_enabled(version='2.235') 2020-06-17T10:25:53Z DEBUG adtrust_is_enabled(version='2.235') 2020-06-17T10:25:53Z DEBUG Starting external process 2020-06-17T10:25:53Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/krb5.keytab'] 2020-06-17T10:25:53Z DEBUG Process finished, return code=0 2020-06-17T10:25:53Z DEBUG stdout= 2020-06-17T10:25:53Z DEBUG stderr= 2020-06-17T10:25:53Z DEBUG Starting external process 2020-06-17T10:25:53Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/samba/samba.keytab'] 2020-06-17T10:25:53Z DEBUG Process finished, return code=0 2020-06-17T10:25:53Z DEBUG stdout= 2020-06-17T10:25:53Z DEBUG stderr= 2020-06-17T10:25:53Z DEBUG Starting external process 2020-06-17T10:25:53Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T10:25:53Z DEBUG Process finished, return code=0 2020-06-17T10:25:53Z DEBUG stdout= 2020-06-17T10:25:53Z DEBUG stderr= 2020-06-17T10:25:53Z DEBUG Starting external process 2020-06-17T10:25:53Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T10:25:53Z DEBUG Process finished, return code=0 2020-06-17T10:25:53Z DEBUG stdout= 2020-06-17T10:25:53Z DEBUG stderr= 2020-06-17T10:25:53Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', version='2.235') 2020-06-17T10:25:53Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', include_master=False, all=False, raw=False, version='2.235') 2020-06-17T10:25:53Z DEBUG Set service ['ADTRUST'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T10:25:53Z DEBUG Set service ['EXTID'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T10:25:53Z DEBUG raw: dns_is_enabled(version='2.235') 2020-06-17T10:25:53Z DEBUG dns_is_enabled(version='2.235') 2020-06-17T10:25:53Z DEBUG raw: dnszone_show('lin.test.lan', version='2.235') 2020-06-17T10:25:53Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:25:53Z DEBUG raw: dns_update_system_records(version='2.235') 2020-06-17T10:25:53Z DEBUG dns_update_system_records(dry_run=False, all=False, raw=False, version='2.235') 2020-06-17T10:25:53Z DEBUG raw: server_find(None, version='2.235', no_members=False, servrole='IPA master') 2020-06-17T10:25:53Z DEBUG server_find(None, all=False, raw=False, version='2.235', no_members=False, pkey_only=False, servrole=('IPA master',)) 2020-06-17T10:25:53Z DEBUG raw: server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, version='2.235') 2020-06-17T10:25:53Z DEBUG server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T10:25:53Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version='2.235') 2020-06-17T10:25:53Z DEBUG topologysuffix_find(None, all=True, raw=True, version='2.235', pkey_only=False) 2020-06-17T10:25:53Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, version='2.235') 2020-06-17T10:25:53Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T10:25:53Z DEBUG raw: dnszone_show(, version='2.235') 2020-06-17T10:25:53Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:25:53Z DEBUG found 1 1 records for freeipaserver.lin.test.lan.: 10.0.0.179 2020-06-17T10:25:53Z DEBUG The DNS response does not contain an answer to the question: freeipaserver.lin.test.lan. IN AAAA 2020-06-17T10:25:53Z DEBUG raw: dnsrecord_mod(, , txtrecord=['"LIN.TEST.LAN"'], version='2.235') 2020-06-17T10:25:53Z DEBUG dnsrecord_mod(, , txtrecord=('"LIN.TEST.LAN"',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:25:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:25:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:25:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:25:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:25:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:25:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:25:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:25:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:25:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:25:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:25:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:25:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:25:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:25:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:25:53Z DEBUG raw: dnsrecord_mod(, , arecord=['10.0.0.179'], version='2.235') 2020-06-17T10:25:53Z DEBUG dnsrecord_mod(, , arecord=('10.0.0.179',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:25:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:25:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:25:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:25:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:25:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:25:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:25:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:25:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:25:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:25:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:25:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:25:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:25:53Z DEBUG raw: location_find(None, version='2.235') 2020-06-17T10:25:53Z DEBUG location_find(None, all=False, raw=False, version='2.235', pkey_only=False) 2020-06-17T10:25:54Z DEBUG Starting external process 2020-06-17T10:25:54Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T10:25:54Z DEBUG Process finished, return code=0 2020-06-17T10:25:54Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T10:25:54Z DEBUG stderr= 2020-06-17T10:25:54Z DEBUG Destroyed connection context.ldap2_139859026836392 2020-06-17T10:25:54Z INFO The ipa-adtrust-install command was successful 2020-06-17T10:26:36Z DEBUG /usr/sbin/ipa-adtrust-install was invoked with options: {'debug': False, 'netbios_name': 'LIN', 'no_msdcs': False, 'rid_base': 1000, 'secondary_rid_base': 100000000, 'unattended': True, 'add_sids': True, 'add_agents': False, 'enable_compat': False} 2020-06-17T10:26:36Z DEBUG missing options might be asked for interactively later 2020-06-17T10:26:36Z DEBUG IPA version 4.8.4-7.module_el8.2.0+374+0d2d74a1 2020-06-17T10:26:36Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:26:36Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T10:26:36Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.aci 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.automember 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.automount 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-06-17T10:26:36Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.batch 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.ca 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.cert 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.config 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.dns 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.group 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-06-17T10:26:36Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.host 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.idoverride-admemberof 2020-06-17T10:26:36Z DEBUG ipaserver.plugins.idoverride-admemberof is not a valid plugin module 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.internal 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.join 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.location 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.migration 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.misc 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.otp 2020-06-17T10:26:36Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.permission 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.ping 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-06-17T10:26:36Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.role 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.schema 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-06-17T10:26:36Z DEBUG importing plugin module ipaserver.plugins.server 2020-06-17T10:26:37Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-06-17T10:26:37Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-06-17T10:26:37Z DEBUG importing plugin module ipaserver.plugins.service 2020-06-17T10:26:37Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-06-17T10:26:37Z DEBUG importing plugin module ipaserver.plugins.session 2020-06-17T10:26:37Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-06-17T10:26:37Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-06-17T10:26:37Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-06-17T10:26:37Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-06-17T10:26:37Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-06-17T10:26:37Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-06-17T10:26:37Z DEBUG importing plugin module ipaserver.plugins.topology 2020-06-17T10:26:37Z DEBUG importing plugin module ipaserver.plugins.trust 2020-06-17T10:26:37Z DEBUG importing plugin module ipaserver.plugins.user 2020-06-17T10:26:37Z DEBUG importing plugin module ipaserver.plugins.vault 2020-06-17T10:26:37Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-06-17T10:26:37Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-06-17T10:26:37Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-06-17T10:26:37Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-06-17T10:26:38Z DEBUG Starting external process 2020-06-17T10:26:38Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T10:26:38Z DEBUG Process finished, return code=0 2020-06-17T10:26:38Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T10:26:38Z DEBUG stderr= 2020-06-17T10:26:38Z DEBUG Created connection context.ldap2_139873955728184 2020-06-17T10:26:38Z DEBUG raw: user_show('admin', version='2.235') 2020-06-17T10:26:38Z DEBUG user_show('admin', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T10:26:38Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T10:26:38Z DEBUG raw: group_show('admins', version='2.235') 2020-06-17T10:26:38Z DEBUG group_show('admins', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T10:26:38Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:26:38Z DEBUG Configuring CIFS 2020-06-17T10:26:38Z DEBUG [1/24]: validate server hostname 2020-06-17T10:26:38Z DEBUG step duration: smb __validate_server_hostname 0.00 sec 2020-06-17T10:26:38Z DEBUG [2/24]: stopping smbd 2020-06-17T10:26:38Z DEBUG Starting external process 2020-06-17T10:26:38Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T10:26:38Z DEBUG Process finished, return code=0 2020-06-17T10:26:38Z DEBUG stdout=active 2020-06-17T10:26:38Z DEBUG stderr= 2020-06-17T10:26:38Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:26:38Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:26:38Z DEBUG Starting external process 2020-06-17T10:26:38Z DEBUG args=['/bin/systemctl', 'stop', 'winbind.service'] 2020-06-17T10:26:38Z DEBUG Process finished, return code=0 2020-06-17T10:26:38Z DEBUG stdout= 2020-06-17T10:26:38Z DEBUG stderr= 2020-06-17T10:26:38Z DEBUG Stop of winbind.service complete 2020-06-17T10:26:38Z DEBUG Starting external process 2020-06-17T10:26:38Z DEBUG args=['/bin/systemctl', 'stop', 'smb.service'] 2020-06-17T10:26:39Z DEBUG Process finished, return code=0 2020-06-17T10:26:39Z DEBUG stdout= 2020-06-17T10:26:39Z DEBUG stderr= 2020-06-17T10:26:39Z DEBUG Stop of smb.service complete 2020-06-17T10:26:39Z DEBUG step duration: smb __stop 0.08 sec 2020-06-17T10:26:39Z DEBUG [3/24]: creating samba domain object 2020-06-17T10:26:39Z DEBUG Samba domain object already exists 2020-06-17T10:26:39Z DEBUG step duration: smb __create_samba_domain_object 0.00 sec 2020-06-17T10:26:39Z DEBUG [4/24]: retrieve local idmap range 2020-06-17T10:26:39Z DEBUG raw: idrange_show('LIN.TEST.LAN_id_range', version='2.235') 2020-06-17T10:26:39Z DEBUG idrange_show('LIN.TEST.LAN_id_range', rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:26:39Z DEBUG step duration: smb __retrieve_local_range 0.00 sec 2020-06-17T10:26:39Z DEBUG [5/24]: creating samba config registry 2020-06-17T10:26:39Z DEBUG Starting external process 2020-06-17T10:26:39Z DEBUG args=['/usr/bin/net', 'conf', 'import', '/tmp/tmprs4s_5hc'] 2020-06-17T10:26:39Z DEBUG Process finished, return code=0 2020-06-17T10:26:39Z DEBUG stdout= 2020-06-17T10:26:39Z DEBUG stderr= 2020-06-17T10:26:39Z DEBUG step duration: smb __write_smb_registry 0.10 sec 2020-06-17T10:26:39Z DEBUG [6/24]: writing samba config file 2020-06-17T10:26:39Z DEBUG step duration: smb __write_smb_conf 0.00 sec 2020-06-17T10:26:39Z DEBUG [7/24]: adding cifs Kerberos principal 2020-06-17T10:26:39Z DEBUG raw: service_add('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', force=True, version='2.235') 2020-06-17T10:26:39Z DEBUG service_add(ipapython.kerberos.Principal('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN'), force=True, skip_host_check=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T10:26:39Z DEBUG raw: host_show('freeipaserver.lin.test.lan', version='2.235') 2020-06-17T10:26:39Z DEBUG host_show('freeipaserver.lin.test.lan', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T10:26:39Z DEBUG Starting external process 2020-06-17T10:26:39Z DEBUG args=['/usr/sbin/ipa-rmkeytab', '--principal', 'cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-k', '/etc/samba/samba.keytab'] 2020-06-17T10:26:39Z DEBUG Process finished, return code=0 2020-06-17T10:26:39Z DEBUG stdout= 2020-06-17T10:26:39Z DEBUG stderr=Suppression du principal cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN 2020-06-17T10:26:39Z DEBUG Removing service credentials cache 2020-06-17T10:26:39Z DEBUG Ccache path: '/var/run/samba/krb5cc_samba' 2020-06-17T10:26:39Z DEBUG Starting external process 2020-06-17T10:26:39Z DEBUG args=['/usr/bin/kdestroy', '-c', '/var/run/samba/krb5cc_samba'] 2020-06-17T10:26:39Z DEBUG Process finished, return code=0 2020-06-17T10:26:39Z DEBUG stdout= 2020-06-17T10:26:39Z DEBUG stderr= 2020-06-17T10:26:39Z DEBUG Starting external process 2020-06-17T10:26:39Z DEBUG args=['/usr/sbin/ipa-getkeytab', '-k', '/etc/samba/samba.keytab', '-p', 'cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:26:39Z DEBUG Process finished, return code=0 2020-06-17T10:26:39Z DEBUG stdout= 2020-06-17T10:26:39Z DEBUG stderr=Récupération du tableau de clés et stockage avec succès dans : /etc/samba/samba.keytab 2020-06-17T10:26:39Z DEBUG step duration: smb request_service_keytab 0.08 sec 2020-06-17T10:26:39Z DEBUG [8/24]: adding cifs and host Kerberos principals to the adtrust agents group 2020-06-17T10:26:39Z DEBUG step duration: smb __setup_group_membership 0.00 sec 2020-06-17T10:26:39Z DEBUG [9/24]: check for cifs services defined on other replicas 2020-06-17T10:26:39Z DEBUG step duration: smb __check_replica 0.00 sec 2020-06-17T10:26:39Z DEBUG [10/24]: adding cifs principal to S4U2Proxy targets 2020-06-17T10:26:39Z DEBUG cifs principal already targeted, nothing to do. 2020-06-17T10:26:39Z DEBUG step duration: smb __add_s4u2proxy_target 0.00 sec 2020-06-17T10:26:39Z DEBUG [11/24]: adding admin(group) SIDs 2020-06-17T10:26:39Z DEBUG Admin SID already set, nothing to do 2020-06-17T10:26:39Z DEBUG Admin group SID already set, nothing to do 2020-06-17T10:26:39Z DEBUG step duration: smb __add_admin_sids 0.00 sec 2020-06-17T10:26:39Z DEBUG [12/24]: adding RID bases 2020-06-17T10:26:39Z DEBUG RID bases already set, nothing to do 2020-06-17T10:26:39Z DEBUG step duration: smb __add_rid_bases 0.00 sec 2020-06-17T10:26:39Z DEBUG [13/24]: updating Kerberos config 2020-06-17T10:26:39Z DEBUG 'dns_lookup_kdc' already set to 'true', nothing to do. 2020-06-17T10:26:39Z DEBUG step duration: smb __update_krb5_conf 0.00 sec 2020-06-17T10:26:39Z DEBUG [14/24]: activating CLDAP plugin 2020-06-17T10:26:39Z DEBUG CLDAP plugin already configured, nothing to do 2020-06-17T10:26:39Z DEBUG step duration: smb __add_cldap_module 0.00 sec 2020-06-17T10:26:39Z DEBUG [15/24]: activating sidgen task 2020-06-17T10:26:39Z DEBUG Sidgen task plugin already configured, nothing to do 2020-06-17T10:26:39Z DEBUG step duration: smb __add_sidgen_task 0.00 sec 2020-06-17T10:26:39Z DEBUG [16/24]: map BUILTIN\Guests to nobody group 2020-06-17T10:26:39Z DEBUG Map BUILTIN\Guests to a group 'nobody' 2020-06-17T10:26:39Z DEBUG Starting external process 2020-06-17T10:26:39Z DEBUG args=['/usr/bin/net', '-s', '/dev/null', 'groupmap', 'add', 'sid=S-1-5-32-546', 'unixgroup=nobody', 'type=builtin'] 2020-06-17T10:26:39Z DEBUG Process finished, return code=255 2020-06-17T10:26:39Z DEBUG stdout=Unix group nobody already mapped to SID S-1-5-32-546 2020-06-17T10:26:39Z DEBUG stderr= 2020-06-17T10:26:39Z DEBUG step duration: smb __map_Guests_to_nobody 0.07 sec 2020-06-17T10:26:39Z DEBUG [17/24]: configuring smbd to start on boot 2020-06-17T10:26:39Z DEBUG Starting external process 2020-06-17T10:26:39Z DEBUG args=['/bin/systemctl', 'is-enabled', 'smb.service'] 2020-06-17T10:26:39Z DEBUG Process finished, return code=0 2020-06-17T10:26:39Z DEBUG stdout=enabled 2020-06-17T10:26:39Z DEBUG stderr= 2020-06-17T10:26:39Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:26:39Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:26:39Z DEBUG Starting external process 2020-06-17T10:26:39Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T10:26:39Z DEBUG Process finished, return code=0 2020-06-17T10:26:39Z DEBUG stdout= 2020-06-17T10:26:39Z DEBUG stderr=Removed /etc/systemd/system/multi-user.target.wants/smb.service. 2020-06-17T10:26:39Z DEBUG service ADTRUST has all config values set 2020-06-17T10:26:39Z DEBUG Starting external process 2020-06-17T10:26:39Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T10:26:39Z DEBUG Process finished, return code=0 2020-06-17T10:26:39Z DEBUG stdout= 2020-06-17T10:26:39Z DEBUG stderr= 2020-06-17T10:26:39Z DEBUG service EXTID has all config values set 2020-06-17T10:26:39Z DEBUG step duration: smb __enable 0.39 sec 2020-06-17T10:26:39Z DEBUG [18/24]: restarting Directory Server to take MS PAC and LDAP plugins changes into account 2020-06-17T10:26:39Z DEBUG Destroyed connection context.ldap2_139873955728184 2020-06-17T10:26:39Z DEBUG Starting external process 2020-06-17T10:26:39Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T10:26:43Z DEBUG Process finished, return code=0 2020-06-17T10:26:43Z DEBUG stdout= 2020-06-17T10:26:43Z DEBUG stderr= 2020-06-17T10:26:43Z DEBUG Restart of dirsrv@LIN-TEST-LAN.service complete 2020-06-17T10:26:43Z DEBUG Created connection context.ldap2_139873955728184 2020-06-17T10:26:43Z DEBUG step duration: smb __restart_dirsrv 3.76 sec 2020-06-17T10:26:43Z DEBUG [19/24]: adding fallback group 2020-06-17T10:26:43Z DEBUG Fallback group already set, nothing to do 2020-06-17T10:26:43Z DEBUG step duration: smb __add_fallback_group 0.00 sec 2020-06-17T10:26:43Z DEBUG [20/24]: adding Default Trust View 2020-06-17T10:26:43Z DEBUG Default Trust View already exists. 2020-06-17T10:26:43Z DEBUG step duration: smb __add_default_trust_view 0.00 sec 2020-06-17T10:26:43Z DEBUG [21/24]: setting SELinux booleans 2020-06-17T10:26:43Z DEBUG Starting external process 2020-06-17T10:26:43Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T10:26:43Z DEBUG Process finished, return code=0 2020-06-17T10:26:43Z DEBUG stdout= 2020-06-17T10:26:43Z DEBUG stderr= 2020-06-17T10:26:43Z DEBUG Starting external process 2020-06-17T10:26:43Z DEBUG args=['/usr/sbin/getsebool', 'samba_portmapper'] 2020-06-17T10:26:43Z DEBUG Process finished, return code=0 2020-06-17T10:26:43Z DEBUG stdout=samba_portmapper --> on 2020-06-17T10:26:43Z DEBUG stderr= 2020-06-17T10:26:43Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:26:43Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T10:26:43Z DEBUG step duration: smb __configure_selinux_for_smbd 0.02 sec 2020-06-17T10:26:43Z DEBUG [22/24]: starting CIFS services 2020-06-17T10:26:43Z DEBUG Starting external process 2020-06-17T10:26:43Z DEBUG args=['/bin/systemctl', 'start', 'smb.service'] 2020-06-17T10:26:43Z DEBUG Process finished, return code=0 2020-06-17T10:26:43Z DEBUG stdout= 2020-06-17T10:26:43Z DEBUG stderr= 2020-06-17T10:26:43Z DEBUG Starting external process 2020-06-17T10:26:43Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T10:26:43Z DEBUG Process finished, return code=0 2020-06-17T10:26:43Z DEBUG stdout=active 2020-06-17T10:26:43Z DEBUG stderr= 2020-06-17T10:26:43Z DEBUG Start of smb.service complete 2020-06-17T10:26:43Z DEBUG Starting external process 2020-06-17T10:26:43Z DEBUG args=['/bin/systemctl', 'start', 'winbind.service'] 2020-06-17T10:26:44Z DEBUG Process finished, return code=0 2020-06-17T10:26:44Z DEBUG stdout= 2020-06-17T10:26:44Z DEBUG stderr= 2020-06-17T10:26:44Z DEBUG Starting external process 2020-06-17T10:26:44Z DEBUG args=['/bin/systemctl', 'is-active', 'winbind.service'] 2020-06-17T10:26:44Z DEBUG Process finished, return code=0 2020-06-17T10:26:44Z DEBUG stdout=active 2020-06-17T10:26:44Z DEBUG stderr= 2020-06-17T10:26:44Z DEBUG Start of winbind.service complete 2020-06-17T10:26:44Z DEBUG step duration: smb __start 0.71 sec 2020-06-17T10:26:44Z DEBUG [23/24]: adding SIDs to existing users and groups 2020-06-17T10:26:44Z DEBUG Starting external process 2020-06-17T10:26:44Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpzdv97ww2', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T10:26:44Z DEBUG Process finished, return code=0 2020-06-17T10:26:44Z DEBUG stdout=add objectClass: top extensibleObject add cn: sidgen add nsslapd-basedn: dc=lin,dc=test,dc=lan add delay: 0 adding new entry "cn=sidgen,cn=ipa-sidgen-task,cn=tasks,cn=config" modify complete 2020-06-17T10:26:44Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T10:26:44Z DEBUG This step may take considerable amount of time, please wait.. 2020-06-17T10:26:45Z DEBUG step duration: smb __add_sids 1.02 sec 2020-06-17T10:26:45Z DEBUG [24/24]: restarting smbd 2020-06-17T10:26:45Z DEBUG step duration: smb __restart_smb 0.00 sec 2020-06-17T10:26:45Z DEBUG Done configuring CIFS. 2020-06-17T10:26:45Z DEBUG service duration: smb 6.25 sec 2020-06-17T10:26:45Z DEBUG raw: update_host_cifs_keytabs 2020-06-17T10:26:45Z DEBUG raw: adtrust_is_enabled(version='2.235') 2020-06-17T10:26:45Z DEBUG adtrust_is_enabled(version='2.235') 2020-06-17T10:26:45Z DEBUG Starting external process 2020-06-17T10:26:45Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/krb5.keytab'] 2020-06-17T10:26:45Z DEBUG Process finished, return code=0 2020-06-17T10:26:45Z DEBUG stdout= 2020-06-17T10:26:45Z DEBUG stderr= 2020-06-17T10:26:45Z DEBUG Starting external process 2020-06-17T10:26:45Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/samba/samba.keytab'] 2020-06-17T10:26:45Z DEBUG Process finished, return code=0 2020-06-17T10:26:45Z DEBUG stdout= 2020-06-17T10:26:45Z DEBUG stderr= 2020-06-17T10:26:45Z DEBUG Starting external process 2020-06-17T10:26:45Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T10:26:45Z DEBUG Process finished, return code=0 2020-06-17T10:26:45Z DEBUG stdout= 2020-06-17T10:26:45Z DEBUG stderr= 2020-06-17T10:26:45Z DEBUG Starting external process 2020-06-17T10:26:45Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T10:26:45Z DEBUG Process finished, return code=0 2020-06-17T10:26:45Z DEBUG stdout= 2020-06-17T10:26:45Z DEBUG stderr= 2020-06-17T10:26:45Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', version='2.235') 2020-06-17T10:26:45Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', include_master=False, all=False, raw=False, version='2.235') 2020-06-17T10:26:45Z DEBUG Set service ['ADTRUST'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T10:26:45Z DEBUG Set service ['EXTID'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T10:26:45Z DEBUG raw: dns_is_enabled(version='2.235') 2020-06-17T10:26:45Z DEBUG dns_is_enabled(version='2.235') 2020-06-17T10:26:45Z DEBUG raw: dnszone_show('lin.test.lan', version='2.235') 2020-06-17T10:26:45Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:26:45Z DEBUG raw: dns_update_system_records(version='2.235') 2020-06-17T10:26:45Z DEBUG dns_update_system_records(dry_run=False, all=False, raw=False, version='2.235') 2020-06-17T10:26:45Z DEBUG raw: server_find(None, version='2.235', no_members=False, servrole='IPA master') 2020-06-17T10:26:45Z DEBUG server_find(None, all=False, raw=False, version='2.235', no_members=False, pkey_only=False, servrole=('IPA master',)) 2020-06-17T10:26:45Z DEBUG raw: server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, version='2.235') 2020-06-17T10:26:45Z DEBUG server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T10:26:45Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version='2.235') 2020-06-17T10:26:45Z DEBUG topologysuffix_find(None, all=True, raw=True, version='2.235', pkey_only=False) 2020-06-17T10:26:45Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, version='2.235') 2020-06-17T10:26:45Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T10:26:45Z DEBUG raw: dnszone_show(, version='2.235') 2020-06-17T10:26:45Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T10:26:45Z DEBUG found 1 1 records for freeipaserver.lin.test.lan.: 10.0.0.179 2020-06-17T10:26:45Z DEBUG The DNS response does not contain an answer to the question: freeipaserver.lin.test.lan. IN AAAA 2020-06-17T10:26:45Z DEBUG raw: dnsrecord_mod(, , txtrecord=['"LIN.TEST.LAN"'], version='2.235') 2020-06-17T10:26:45Z DEBUG dnsrecord_mod(, , txtrecord=('"LIN.TEST.LAN"',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:26:45Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:26:45Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:26:45Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:26:45Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:26:45Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:26:45Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:26:45Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:26:45Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:26:45Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:26:45Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:26:45Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:26:45Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:26:45Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:26:45Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:26:45Z DEBUG raw: dnsrecord_mod(, , arecord=['10.0.0.179'], version='2.235') 2020-06-17T10:26:45Z DEBUG dnsrecord_mod(, , arecord=('10.0.0.179',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:26:45Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:26:45Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:26:45Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:26:45Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:26:45Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:26:45Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:26:45Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:26:45Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:26:45Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:26:45Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:26:45Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T10:26:45Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T10:26:45Z DEBUG raw: location_find(None, version='2.235') 2020-06-17T10:26:45Z DEBUG location_find(None, all=False, raw=False, version='2.235', pkey_only=False) 2020-06-17T10:26:45Z DEBUG Starting external process 2020-06-17T10:26:45Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T10:26:45Z DEBUG Process finished, return code=0 2020-06-17T10:26:45Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T10:26:45Z DEBUG stderr= 2020-06-17T10:26:45Z DEBUG Destroyed connection context.ldap2_139873955728184 2020-06-17T10:26:45Z INFO The ipa-adtrust-install command was successful 2020-06-17T14:06:17Z DEBUG /usr/sbin/ipa-adtrust-install was invoked with options: {'debug': False, 'netbios_name': 'LIN', 'no_msdcs': False, 'rid_base': 1000, 'secondary_rid_base': 100000000, 'unattended': True, 'add_sids': True, 'add_agents': False, 'enable_compat': False} 2020-06-17T14:06:17Z DEBUG missing options might be asked for interactively later 2020-06-17T14:06:17Z DEBUG IPA version 4.8.4-7.module_el8.2.0+374+0d2d74a1 2020-06-17T14:06:17Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T14:06:17Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T14:06:17Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-06-17T14:06:17Z DEBUG importing plugin module ipaserver.plugins.aci 2020-06-17T14:06:17Z DEBUG importing plugin module ipaserver.plugins.automember 2020-06-17T14:06:17Z DEBUG importing plugin module ipaserver.plugins.automount 2020-06-17T14:06:17Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-06-17T14:06:17Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-06-17T14:06:17Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-06-17T14:06:17Z DEBUG importing plugin module ipaserver.plugins.batch 2020-06-17T14:06:17Z DEBUG importing plugin module ipaserver.plugins.ca 2020-06-17T14:06:17Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-06-17T14:06:17Z DEBUG importing plugin module ipaserver.plugins.cert 2020-06-17T14:06:17Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-06-17T14:06:17Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-06-17T14:06:17Z DEBUG importing plugin module ipaserver.plugins.config 2020-06-17T14:06:17Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-06-17T14:06:17Z DEBUG importing plugin module ipaserver.plugins.dns 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.group 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-06-17T14:06:18Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.host 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.idoverride-admemberof 2020-06-17T14:06:18Z DEBUG ipaserver.plugins.idoverride-admemberof is not a valid plugin module 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.internal 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.join 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.location 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.migration 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.misc 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.otp 2020-06-17T14:06:18Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.permission 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.ping 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-06-17T14:06:18Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.role 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.schema 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.server 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.service 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.session 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-06-17T14:06:18Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.topology 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.trust 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.user 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.vault 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-06-17T14:06:18Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-06-17T14:06:18Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-06-17T14:06:19Z DEBUG Starting external process 2020-06-17T14:06:19Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T14:06:19Z DEBUG Process finished, return code=0 2020-06-17T14:06:19Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T14:06:19Z DEBUG stderr= 2020-06-17T14:06:20Z DEBUG Created connection context.ldap2_140082342173496 2020-06-17T14:06:20Z DEBUG raw: user_show('admin', version='2.235') 2020-06-17T14:06:20Z DEBUG user_show('admin', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:06:20Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T14:06:20Z DEBUG raw: group_show('admins', version='2.235') 2020-06-17T14:06:20Z DEBUG group_show('admins', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:06:20Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:06:20Z DEBUG Configuring CIFS 2020-06-17T14:06:20Z DEBUG [1/24]: validate server hostname 2020-06-17T14:06:20Z DEBUG step duration: smb __validate_server_hostname 0.00 sec 2020-06-17T14:06:20Z DEBUG [2/24]: stopping smbd 2020-06-17T14:06:20Z DEBUG Starting external process 2020-06-17T14:06:20Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T14:06:20Z DEBUG Process finished, return code=0 2020-06-17T14:06:20Z DEBUG stdout=active 2020-06-17T14:06:20Z DEBUG stderr= 2020-06-17T14:06:20Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:06:20Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:06:20Z DEBUG Starting external process 2020-06-17T14:06:20Z DEBUG args=['/bin/systemctl', 'stop', 'winbind.service'] 2020-06-17T14:06:20Z DEBUG Process finished, return code=0 2020-06-17T14:06:20Z DEBUG stdout= 2020-06-17T14:06:20Z DEBUG stderr= 2020-06-17T14:06:20Z DEBUG Stop of winbind.service complete 2020-06-17T14:06:20Z DEBUG Starting external process 2020-06-17T14:06:20Z DEBUG args=['/bin/systemctl', 'stop', 'smb.service'] 2020-06-17T14:06:20Z DEBUG Process finished, return code=0 2020-06-17T14:06:20Z DEBUG stdout= 2020-06-17T14:06:20Z DEBUG stderr= 2020-06-17T14:06:20Z DEBUG Stop of smb.service complete 2020-06-17T14:06:20Z DEBUG step duration: smb __stop 0.09 sec 2020-06-17T14:06:20Z DEBUG [3/24]: creating samba domain object 2020-06-17T14:06:20Z DEBUG Samba domain object already exists 2020-06-17T14:06:20Z DEBUG step duration: smb __create_samba_domain_object 0.00 sec 2020-06-17T14:06:20Z DEBUG [4/24]: retrieve local idmap range 2020-06-17T14:06:20Z DEBUG raw: idrange_show('LIN.TEST.LAN_id_range', version='2.235') 2020-06-17T14:06:20Z DEBUG idrange_show('LIN.TEST.LAN_id_range', rights=False, all=False, raw=False, version='2.235') 2020-06-17T14:06:20Z DEBUG step duration: smb __retrieve_local_range 0.00 sec 2020-06-17T14:06:20Z DEBUG [5/24]: creating samba config registry 2020-06-17T14:06:20Z DEBUG Starting external process 2020-06-17T14:06:20Z DEBUG args=['/usr/bin/net', 'conf', 'import', '/tmp/tmpus2y2rnn'] 2020-06-17T14:06:20Z DEBUG Process finished, return code=0 2020-06-17T14:06:20Z DEBUG stdout= 2020-06-17T14:06:20Z DEBUG stderr= 2020-06-17T14:06:20Z DEBUG step duration: smb __write_smb_registry 0.11 sec 2020-06-17T14:06:20Z DEBUG [6/24]: writing samba config file 2020-06-17T14:06:20Z DEBUG step duration: smb __write_smb_conf 0.00 sec 2020-06-17T14:06:20Z DEBUG [7/24]: adding cifs Kerberos principal 2020-06-17T14:06:20Z DEBUG raw: service_add('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', force=True, version='2.235') 2020-06-17T14:06:20Z DEBUG service_add(ipapython.kerberos.Principal('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN'), force=True, skip_host_check=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:06:20Z DEBUG raw: host_show('freeipaserver.lin.test.lan', version='2.235') 2020-06-17T14:06:20Z DEBUG host_show('freeipaserver.lin.test.lan', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:06:20Z DEBUG Starting external process 2020-06-17T14:06:20Z DEBUG args=['/usr/sbin/ipa-rmkeytab', '--principal', 'cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-k', '/etc/samba/samba.keytab'] 2020-06-17T14:06:20Z DEBUG Process finished, return code=0 2020-06-17T14:06:20Z DEBUG stdout= 2020-06-17T14:06:20Z DEBUG stderr=Suppression du principal cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN 2020-06-17T14:06:20Z DEBUG Removing service credentials cache 2020-06-17T14:06:20Z DEBUG Ccache path: '/var/run/samba/krb5cc_samba' 2020-06-17T14:06:20Z DEBUG Starting external process 2020-06-17T14:06:20Z DEBUG args=['/usr/bin/kdestroy', '-c', '/var/run/samba/krb5cc_samba'] 2020-06-17T14:06:20Z DEBUG Process finished, return code=0 2020-06-17T14:06:20Z DEBUG stdout= 2020-06-17T14:06:20Z DEBUG stderr= 2020-06-17T14:06:20Z DEBUG Starting external process 2020-06-17T14:06:20Z DEBUG args=['/usr/sbin/ipa-getkeytab', '-k', '/etc/samba/samba.keytab', '-p', 'cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T14:06:20Z DEBUG Process finished, return code=0 2020-06-17T14:06:20Z DEBUG stdout= 2020-06-17T14:06:20Z DEBUG stderr=Récupération du tableau de clés et stockage avec succès dans : /etc/samba/samba.keytab 2020-06-17T14:06:20Z DEBUG step duration: smb request_service_keytab 0.08 sec 2020-06-17T14:06:20Z DEBUG [8/24]: adding cifs and host Kerberos principals to the adtrust agents group 2020-06-17T14:06:20Z DEBUG step duration: smb __setup_group_membership 0.00 sec 2020-06-17T14:06:20Z DEBUG [9/24]: check for cifs services defined on other replicas 2020-06-17T14:06:20Z DEBUG step duration: smb __check_replica 0.00 sec 2020-06-17T14:06:20Z DEBUG [10/24]: adding cifs principal to S4U2Proxy targets 2020-06-17T14:06:20Z DEBUG cifs principal already targeted, nothing to do. 2020-06-17T14:06:20Z DEBUG step duration: smb __add_s4u2proxy_target 0.00 sec 2020-06-17T14:06:20Z DEBUG [11/24]: adding admin(group) SIDs 2020-06-17T14:06:20Z DEBUG Admin SID already set, nothing to do 2020-06-17T14:06:20Z DEBUG Admin group SID already set, nothing to do 2020-06-17T14:06:20Z DEBUG step duration: smb __add_admin_sids 0.00 sec 2020-06-17T14:06:20Z DEBUG [12/24]: adding RID bases 2020-06-17T14:06:20Z DEBUG RID bases already set, nothing to do 2020-06-17T14:06:20Z DEBUG step duration: smb __add_rid_bases 0.00 sec 2020-06-17T14:06:20Z DEBUG [13/24]: updating Kerberos config 2020-06-17T14:06:20Z DEBUG 'dns_lookup_kdc' already set to 'true', nothing to do. 2020-06-17T14:06:20Z DEBUG step duration: smb __update_krb5_conf 0.00 sec 2020-06-17T14:06:20Z DEBUG [14/24]: activating CLDAP plugin 2020-06-17T14:06:20Z DEBUG CLDAP plugin already configured, nothing to do 2020-06-17T14:06:20Z DEBUG step duration: smb __add_cldap_module 0.00 sec 2020-06-17T14:06:20Z DEBUG [15/24]: activating sidgen task 2020-06-17T14:06:20Z DEBUG Sidgen task plugin already configured, nothing to do 2020-06-17T14:06:20Z DEBUG step duration: smb __add_sidgen_task 0.00 sec 2020-06-17T14:06:20Z DEBUG [16/24]: map BUILTIN\Guests to nobody group 2020-06-17T14:06:20Z DEBUG Map BUILTIN\Guests to a group 'nobody' 2020-06-17T14:06:20Z DEBUG Starting external process 2020-06-17T14:06:20Z DEBUG args=['/usr/bin/net', '-s', '/dev/null', 'groupmap', 'add', 'sid=S-1-5-32-546', 'unixgroup=nobody', 'type=builtin'] 2020-06-17T14:06:20Z DEBUG Process finished, return code=255 2020-06-17T14:06:20Z DEBUG stdout=Unix group nobody already mapped to SID S-1-5-32-546 2020-06-17T14:06:20Z DEBUG stderr= 2020-06-17T14:06:20Z DEBUG step duration: smb __map_Guests_to_nobody 0.08 sec 2020-06-17T14:06:20Z DEBUG [17/24]: configuring smbd to start on boot 2020-06-17T14:06:20Z DEBUG Starting external process 2020-06-17T14:06:20Z DEBUG args=['/bin/systemctl', 'is-enabled', 'smb.service'] 2020-06-17T14:06:20Z DEBUG Process finished, return code=0 2020-06-17T14:06:20Z DEBUG stdout=enabled 2020-06-17T14:06:20Z DEBUG stderr= 2020-06-17T14:06:20Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:06:20Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:06:20Z DEBUG Starting external process 2020-06-17T14:06:20Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T14:06:20Z DEBUG Process finished, return code=0 2020-06-17T14:06:20Z DEBUG stdout= 2020-06-17T14:06:20Z DEBUG stderr=Removed /etc/systemd/system/multi-user.target.wants/smb.service. 2020-06-17T14:06:20Z DEBUG service ADTRUST has all config values set 2020-06-17T14:06:20Z DEBUG Starting external process 2020-06-17T14:06:20Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T14:06:21Z DEBUG Process finished, return code=0 2020-06-17T14:06:21Z DEBUG stdout= 2020-06-17T14:06:21Z DEBUG stderr= 2020-06-17T14:06:21Z DEBUG service EXTID has all config values set 2020-06-17T14:06:21Z DEBUG step duration: smb __enable 0.41 sec 2020-06-17T14:06:21Z DEBUG [18/24]: restarting Directory Server to take MS PAC and LDAP plugins changes into account 2020-06-17T14:06:21Z DEBUG Destroyed connection context.ldap2_140082342173496 2020-06-17T14:06:21Z DEBUG Starting external process 2020-06-17T14:06:21Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T14:06:25Z DEBUG Process finished, return code=0 2020-06-17T14:06:25Z DEBUG stdout= 2020-06-17T14:06:25Z DEBUG stderr= 2020-06-17T14:06:25Z DEBUG Restart of dirsrv@LIN-TEST-LAN.service complete 2020-06-17T14:06:25Z DEBUG Created connection context.ldap2_140082342173496 2020-06-17T14:06:25Z DEBUG step duration: smb __restart_dirsrv 4.12 sec 2020-06-17T14:06:25Z DEBUG [19/24]: adding fallback group 2020-06-17T14:06:25Z DEBUG Fallback group already set, nothing to do 2020-06-17T14:06:25Z DEBUG step duration: smb __add_fallback_group 0.00 sec 2020-06-17T14:06:25Z DEBUG [20/24]: adding Default Trust View 2020-06-17T14:06:25Z DEBUG Default Trust View already exists. 2020-06-17T14:06:25Z DEBUG step duration: smb __add_default_trust_view 0.00 sec 2020-06-17T14:06:25Z DEBUG [21/24]: setting SELinux booleans 2020-06-17T14:06:25Z DEBUG Starting external process 2020-06-17T14:06:25Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T14:06:25Z DEBUG Process finished, return code=0 2020-06-17T14:06:25Z DEBUG stdout= 2020-06-17T14:06:25Z DEBUG stderr= 2020-06-17T14:06:25Z DEBUG Starting external process 2020-06-17T14:06:25Z DEBUG args=['/usr/sbin/getsebool', 'samba_portmapper'] 2020-06-17T14:06:25Z DEBUG Process finished, return code=0 2020-06-17T14:06:25Z DEBUG stdout=samba_portmapper --> on 2020-06-17T14:06:25Z DEBUG stderr= 2020-06-17T14:06:25Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:06:25Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:06:25Z DEBUG step duration: smb __configure_selinux_for_smbd 0.02 sec 2020-06-17T14:06:25Z DEBUG [22/24]: starting CIFS services 2020-06-17T14:06:25Z DEBUG Starting external process 2020-06-17T14:06:25Z DEBUG args=['/bin/systemctl', 'start', 'smb.service'] 2020-06-17T14:06:25Z DEBUG Process finished, return code=0 2020-06-17T14:06:25Z DEBUG stdout= 2020-06-17T14:06:25Z DEBUG stderr= 2020-06-17T14:06:25Z DEBUG Starting external process 2020-06-17T14:06:25Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T14:06:25Z DEBUG Process finished, return code=0 2020-06-17T14:06:25Z DEBUG stdout=active 2020-06-17T14:06:25Z DEBUG stderr= 2020-06-17T14:06:25Z DEBUG Start of smb.service complete 2020-06-17T14:06:25Z DEBUG Starting external process 2020-06-17T14:06:25Z DEBUG args=['/bin/systemctl', 'start', 'winbind.service'] 2020-06-17T14:06:25Z DEBUG Process finished, return code=0 2020-06-17T14:06:25Z DEBUG stdout= 2020-06-17T14:06:25Z DEBUG stderr= 2020-06-17T14:06:25Z DEBUG Starting external process 2020-06-17T14:06:25Z DEBUG args=['/bin/systemctl', 'is-active', 'winbind.service'] 2020-06-17T14:06:25Z DEBUG Process finished, return code=0 2020-06-17T14:06:25Z DEBUG stdout=active 2020-06-17T14:06:25Z DEBUG stderr= 2020-06-17T14:06:25Z DEBUG Start of winbind.service complete 2020-06-17T14:06:25Z DEBUG step duration: smb __start 0.69 sec 2020-06-17T14:06:25Z DEBUG [23/24]: adding SIDs to existing users and groups 2020-06-17T14:06:25Z DEBUG Starting external process 2020-06-17T14:06:25Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp3yu9b96h', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T14:06:25Z DEBUG Process finished, return code=0 2020-06-17T14:06:25Z DEBUG stdout=add objectClass: top extensibleObject add cn: sidgen add nsslapd-basedn: dc=lin,dc=test,dc=lan add delay: 0 adding new entry "cn=sidgen,cn=ipa-sidgen-task,cn=tasks,cn=config" modify complete 2020-06-17T14:06:25Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T14:06:25Z DEBUG This step may take considerable amount of time, please wait.. 2020-06-17T14:06:26Z DEBUG step duration: smb __add_sids 1.02 sec 2020-06-17T14:06:26Z DEBUG [24/24]: restarting smbd 2020-06-17T14:06:26Z DEBUG step duration: smb __restart_smb 0.00 sec 2020-06-17T14:06:26Z DEBUG Done configuring CIFS. 2020-06-17T14:06:26Z DEBUG service duration: smb 6.63 sec 2020-06-17T14:06:26Z DEBUG raw: update_host_cifs_keytabs 2020-06-17T14:06:26Z DEBUG raw: adtrust_is_enabled(version='2.235') 2020-06-17T14:06:26Z DEBUG adtrust_is_enabled(version='2.235') 2020-06-17T14:06:26Z DEBUG Starting external process 2020-06-17T14:06:26Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/krb5.keytab'] 2020-06-17T14:06:26Z DEBUG Process finished, return code=0 2020-06-17T14:06:26Z DEBUG stdout= 2020-06-17T14:06:26Z DEBUG stderr= 2020-06-17T14:06:26Z DEBUG Starting external process 2020-06-17T14:06:26Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/samba/samba.keytab'] 2020-06-17T14:06:26Z DEBUG Process finished, return code=0 2020-06-17T14:06:26Z DEBUG stdout= 2020-06-17T14:06:26Z DEBUG stderr= 2020-06-17T14:06:26Z DEBUG Starting external process 2020-06-17T14:06:26Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T14:06:26Z DEBUG Process finished, return code=0 2020-06-17T14:06:26Z DEBUG stdout= 2020-06-17T14:06:26Z DEBUG stderr= 2020-06-17T14:06:26Z DEBUG Starting external process 2020-06-17T14:06:26Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T14:06:26Z DEBUG Process finished, return code=0 2020-06-17T14:06:26Z DEBUG stdout= 2020-06-17T14:06:26Z DEBUG stderr= 2020-06-17T14:06:26Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', version='2.235') 2020-06-17T14:06:26Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', include_master=False, all=False, raw=False, version='2.235') 2020-06-17T14:06:26Z DEBUG Set service ['ADTRUST'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T14:06:26Z DEBUG Set service ['EXTID'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T14:06:26Z DEBUG raw: dns_is_enabled(version='2.235') 2020-06-17T14:06:26Z DEBUG dns_is_enabled(version='2.235') 2020-06-17T14:06:26Z DEBUG raw: dnszone_show('lin.test.lan', version='2.235') 2020-06-17T14:06:26Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T14:06:26Z DEBUG raw: dns_update_system_records(version='2.235') 2020-06-17T14:06:26Z DEBUG dns_update_system_records(dry_run=False, all=False, raw=False, version='2.235') 2020-06-17T14:06:26Z DEBUG raw: server_find(None, version='2.235', no_members=False, servrole='IPA master') 2020-06-17T14:06:26Z DEBUG server_find(None, all=False, raw=False, version='2.235', no_members=False, pkey_only=False, servrole=('IPA master',)) 2020-06-17T14:06:26Z DEBUG raw: server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, version='2.235') 2020-06-17T14:06:26Z DEBUG server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T14:06:26Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version='2.235') 2020-06-17T14:06:26Z DEBUG topologysuffix_find(None, all=True, raw=True, version='2.235', pkey_only=False) 2020-06-17T14:06:26Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, version='2.235') 2020-06-17T14:06:26Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T14:06:26Z DEBUG raw: dnszone_show(, version='2.235') 2020-06-17T14:06:26Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T14:06:26Z DEBUG found 1 1 records for freeipaserver.lin.test.lan.: 10.0.0.179 2020-06-17T14:06:26Z DEBUG The DNS response does not contain an answer to the question: freeipaserver.lin.test.lan. IN AAAA 2020-06-17T14:06:26Z DEBUG raw: dnsrecord_mod(, , txtrecord=['"LIN.TEST.LAN"'], version='2.235') 2020-06-17T14:06:26Z DEBUG dnsrecord_mod(, , txtrecord=('"LIN.TEST.LAN"',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:06:26Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:06:26Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:06:26Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:06:26Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:06:26Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:06:26Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:06:27Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:06:27Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:06:27Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:06:27Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:06:27Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:06:27Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:06:27Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:06:27Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:06:27Z DEBUG raw: dnsrecord_mod(, , arecord=['10.0.0.179'], version='2.235') 2020-06-17T14:06:27Z DEBUG dnsrecord_mod(, , arecord=('10.0.0.179',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:06:27Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:06:27Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:06:27Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:06:27Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:06:27Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:06:27Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:06:27Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:06:27Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:06:27Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:06:27Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:06:27Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:06:27Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:06:27Z DEBUG raw: location_find(None, version='2.235') 2020-06-17T14:06:27Z DEBUG location_find(None, all=False, raw=False, version='2.235', pkey_only=False) 2020-06-17T14:06:27Z DEBUG Starting external process 2020-06-17T14:06:27Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T14:06:27Z DEBUG Process finished, return code=0 2020-06-17T14:06:27Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T14:06:27Z DEBUG stderr= 2020-06-17T14:06:27Z DEBUG Destroyed connection context.ldap2_140082342173496 2020-06-17T14:06:27Z INFO The ipa-adtrust-install command was successful 2020-06-17T14:11:06Z DEBUG /usr/sbin/ipa-adtrust-install was invoked with options: {'debug': False, 'netbios_name': 'LIN', 'no_msdcs': False, 'rid_base': 1000, 'secondary_rid_base': 100000000, 'unattended': True, 'add_sids': True, 'add_agents': False, 'enable_compat': False} 2020-06-17T14:11:06Z DEBUG missing options might be asked for interactively later 2020-06-17T14:11:06Z DEBUG IPA version 4.8.4-7.module_el8.2.0+374+0d2d74a1 2020-06-17T14:11:06Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T14:11:06Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T14:11:06Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.aci 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.automember 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.automount 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-06-17T14:11:06Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.batch 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.ca 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.cert 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.config 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.dns 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.group 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-06-17T14:11:06Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.host 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.idoverride-admemberof 2020-06-17T14:11:06Z DEBUG ipaserver.plugins.idoverride-admemberof is not a valid plugin module 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.internal 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.join 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.location 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.migration 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.misc 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.otp 2020-06-17T14:11:06Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.permission 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.ping 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-06-17T14:11:06Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.role 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.schema 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-06-17T14:11:06Z DEBUG importing plugin module ipaserver.plugins.server 2020-06-17T14:11:07Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-06-17T14:11:07Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-06-17T14:11:07Z DEBUG importing plugin module ipaserver.plugins.service 2020-06-17T14:11:07Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-06-17T14:11:07Z DEBUG importing plugin module ipaserver.plugins.session 2020-06-17T14:11:07Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-06-17T14:11:07Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-06-17T14:11:07Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-06-17T14:11:07Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-06-17T14:11:07Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-06-17T14:11:07Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-06-17T14:11:07Z DEBUG importing plugin module ipaserver.plugins.topology 2020-06-17T14:11:07Z DEBUG importing plugin module ipaserver.plugins.trust 2020-06-17T14:11:07Z DEBUG importing plugin module ipaserver.plugins.user 2020-06-17T14:11:07Z DEBUG importing plugin module ipaserver.plugins.vault 2020-06-17T14:11:07Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-06-17T14:11:07Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-06-17T14:11:07Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-06-17T14:11:07Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-06-17T14:11:08Z DEBUG Starting external process 2020-06-17T14:11:08Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T14:11:08Z DEBUG Process finished, return code=0 2020-06-17T14:11:08Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T14:11:08Z DEBUG stderr= 2020-06-17T14:11:08Z DEBUG Created connection context.ldap2_140184533109784 2020-06-17T14:11:08Z DEBUG raw: user_show('admin', version='2.235') 2020-06-17T14:11:08Z DEBUG user_show('admin', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:11:08Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T14:11:08Z DEBUG raw: group_show('admins', version='2.235') 2020-06-17T14:11:08Z DEBUG group_show('admins', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:11:08Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:11:08Z DEBUG Configuring CIFS 2020-06-17T14:11:08Z DEBUG [1/24]: validate server hostname 2020-06-17T14:11:08Z DEBUG step duration: smb __validate_server_hostname 0.00 sec 2020-06-17T14:11:08Z DEBUG [2/24]: stopping smbd 2020-06-17T14:11:08Z DEBUG Starting external process 2020-06-17T14:11:08Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T14:11:08Z DEBUG Process finished, return code=0 2020-06-17T14:11:08Z DEBUG stdout=active 2020-06-17T14:11:08Z DEBUG stderr= 2020-06-17T14:11:08Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:11:08Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:11:08Z DEBUG Starting external process 2020-06-17T14:11:08Z DEBUG args=['/bin/systemctl', 'stop', 'winbind.service'] 2020-06-17T14:11:08Z DEBUG Process finished, return code=0 2020-06-17T14:11:08Z DEBUG stdout= 2020-06-17T14:11:08Z DEBUG stderr= 2020-06-17T14:11:08Z DEBUG Stop of winbind.service complete 2020-06-17T14:11:08Z DEBUG Starting external process 2020-06-17T14:11:08Z DEBUG args=['/bin/systemctl', 'stop', 'smb.service'] 2020-06-17T14:11:09Z DEBUG Process finished, return code=0 2020-06-17T14:11:09Z DEBUG stdout= 2020-06-17T14:11:09Z DEBUG stderr= 2020-06-17T14:11:09Z DEBUG Stop of smb.service complete 2020-06-17T14:11:09Z DEBUG step duration: smb __stop 0.09 sec 2020-06-17T14:11:09Z DEBUG [3/24]: creating samba domain object 2020-06-17T14:11:09Z DEBUG Samba domain object already exists 2020-06-17T14:11:09Z DEBUG step duration: smb __create_samba_domain_object 0.00 sec 2020-06-17T14:11:09Z DEBUG [4/24]: retrieve local idmap range 2020-06-17T14:11:09Z DEBUG raw: idrange_show('LIN.TEST.LAN_id_range', version='2.235') 2020-06-17T14:11:09Z DEBUG idrange_show('LIN.TEST.LAN_id_range', rights=False, all=False, raw=False, version='2.235') 2020-06-17T14:11:09Z DEBUG step duration: smb __retrieve_local_range 0.00 sec 2020-06-17T14:11:09Z DEBUG [5/24]: creating samba config registry 2020-06-17T14:11:09Z DEBUG Starting external process 2020-06-17T14:11:09Z DEBUG args=['/usr/bin/net', 'conf', 'import', '/tmp/tmpn7xmw1gg'] 2020-06-17T14:11:09Z DEBUG Process finished, return code=0 2020-06-17T14:11:09Z DEBUG stdout= 2020-06-17T14:11:09Z DEBUG stderr= 2020-06-17T14:11:09Z DEBUG step duration: smb __write_smb_registry 0.09 sec 2020-06-17T14:11:09Z DEBUG [6/24]: writing samba config file 2020-06-17T14:11:09Z DEBUG step duration: smb __write_smb_conf 0.00 sec 2020-06-17T14:11:09Z DEBUG [7/24]: adding cifs Kerberos principal 2020-06-17T14:11:09Z DEBUG raw: service_add('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', force=True, version='2.235') 2020-06-17T14:11:09Z DEBUG service_add(ipapython.kerberos.Principal('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN'), force=True, skip_host_check=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:11:09Z DEBUG raw: host_show('freeipaserver.lin.test.lan', version='2.235') 2020-06-17T14:11:09Z DEBUG host_show('freeipaserver.lin.test.lan', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:11:09Z DEBUG Starting external process 2020-06-17T14:11:09Z DEBUG args=['/usr/sbin/ipa-rmkeytab', '--principal', 'cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-k', '/etc/samba/samba.keytab'] 2020-06-17T14:11:09Z DEBUG Process finished, return code=0 2020-06-17T14:11:09Z DEBUG stdout= 2020-06-17T14:11:09Z DEBUG stderr=Suppression du principal cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN 2020-06-17T14:11:09Z DEBUG Removing service credentials cache 2020-06-17T14:11:09Z DEBUG Ccache path: '/var/run/samba/krb5cc_samba' 2020-06-17T14:11:09Z DEBUG Starting external process 2020-06-17T14:11:09Z DEBUG args=['/usr/bin/kdestroy', '-c', '/var/run/samba/krb5cc_samba'] 2020-06-17T14:11:09Z DEBUG Process finished, return code=0 2020-06-17T14:11:09Z DEBUG stdout= 2020-06-17T14:11:09Z DEBUG stderr= 2020-06-17T14:11:09Z DEBUG Starting external process 2020-06-17T14:11:09Z DEBUG args=['/usr/sbin/ipa-getkeytab', '-k', '/etc/samba/samba.keytab', '-p', 'cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T14:11:09Z DEBUG Process finished, return code=0 2020-06-17T14:11:09Z DEBUG stdout= 2020-06-17T14:11:09Z DEBUG stderr=Récupération du tableau de clés et stockage avec succès dans : /etc/samba/samba.keytab 2020-06-17T14:11:09Z DEBUG step duration: smb request_service_keytab 0.07 sec 2020-06-17T14:11:09Z DEBUG [8/24]: adding cifs and host Kerberos principals to the adtrust agents group 2020-06-17T14:11:09Z DEBUG step duration: smb __setup_group_membership 0.00 sec 2020-06-17T14:11:09Z DEBUG [9/24]: check for cifs services defined on other replicas 2020-06-17T14:11:09Z DEBUG step duration: smb __check_replica 0.00 sec 2020-06-17T14:11:09Z DEBUG [10/24]: adding cifs principal to S4U2Proxy targets 2020-06-17T14:11:09Z DEBUG cifs principal already targeted, nothing to do. 2020-06-17T14:11:09Z DEBUG step duration: smb __add_s4u2proxy_target 0.00 sec 2020-06-17T14:11:09Z DEBUG [11/24]: adding admin(group) SIDs 2020-06-17T14:11:09Z DEBUG Admin SID already set, nothing to do 2020-06-17T14:11:09Z DEBUG Admin group SID already set, nothing to do 2020-06-17T14:11:09Z DEBUG step duration: smb __add_admin_sids 0.00 sec 2020-06-17T14:11:09Z DEBUG [12/24]: adding RID bases 2020-06-17T14:11:09Z DEBUG RID bases already set, nothing to do 2020-06-17T14:11:09Z DEBUG step duration: smb __add_rid_bases 0.00 sec 2020-06-17T14:11:09Z DEBUG [13/24]: updating Kerberos config 2020-06-17T14:11:09Z DEBUG 'dns_lookup_kdc' already set to 'true', nothing to do. 2020-06-17T14:11:09Z DEBUG step duration: smb __update_krb5_conf 0.00 sec 2020-06-17T14:11:09Z DEBUG [14/24]: activating CLDAP plugin 2020-06-17T14:11:09Z DEBUG CLDAP plugin already configured, nothing to do 2020-06-17T14:11:09Z DEBUG step duration: smb __add_cldap_module 0.00 sec 2020-06-17T14:11:09Z DEBUG [15/24]: activating sidgen task 2020-06-17T14:11:09Z DEBUG Sidgen task plugin already configured, nothing to do 2020-06-17T14:11:09Z DEBUG step duration: smb __add_sidgen_task 0.00 sec 2020-06-17T14:11:09Z DEBUG [16/24]: map BUILTIN\Guests to nobody group 2020-06-17T14:11:09Z DEBUG Map BUILTIN\Guests to a group 'nobody' 2020-06-17T14:11:09Z DEBUG Starting external process 2020-06-17T14:11:09Z DEBUG args=['/usr/bin/net', '-s', '/dev/null', 'groupmap', 'add', 'sid=S-1-5-32-546', 'unixgroup=nobody', 'type=builtin'] 2020-06-17T14:11:09Z DEBUG Process finished, return code=255 2020-06-17T14:11:09Z DEBUG stdout=Unix group nobody already mapped to SID S-1-5-32-546 2020-06-17T14:11:09Z DEBUG stderr= 2020-06-17T14:11:09Z DEBUG step duration: smb __map_Guests_to_nobody 0.07 sec 2020-06-17T14:11:09Z DEBUG [17/24]: configuring smbd to start on boot 2020-06-17T14:11:09Z DEBUG Starting external process 2020-06-17T14:11:09Z DEBUG args=['/bin/systemctl', 'is-enabled', 'smb.service'] 2020-06-17T14:11:09Z DEBUG Process finished, return code=0 2020-06-17T14:11:09Z DEBUG stdout=enabled 2020-06-17T14:11:09Z DEBUG stderr= 2020-06-17T14:11:09Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:11:09Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:11:09Z DEBUG Starting external process 2020-06-17T14:11:09Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T14:11:09Z DEBUG Process finished, return code=0 2020-06-17T14:11:09Z DEBUG stdout= 2020-06-17T14:11:09Z DEBUG stderr=Removed /etc/systemd/system/multi-user.target.wants/smb.service. 2020-06-17T14:11:09Z DEBUG service ADTRUST has all config values set 2020-06-17T14:11:09Z DEBUG Starting external process 2020-06-17T14:11:09Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T14:11:09Z DEBUG Process finished, return code=0 2020-06-17T14:11:09Z DEBUG stdout= 2020-06-17T14:11:09Z DEBUG stderr= 2020-06-17T14:11:09Z DEBUG service EXTID has all config values set 2020-06-17T14:11:09Z DEBUG step duration: smb __enable 0.39 sec 2020-06-17T14:11:09Z DEBUG [18/24]: restarting Directory Server to take MS PAC and LDAP plugins changes into account 2020-06-17T14:11:09Z DEBUG Destroyed connection context.ldap2_140184533109784 2020-06-17T14:11:09Z DEBUG Starting external process 2020-06-17T14:11:09Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T14:11:14Z DEBUG Process finished, return code=0 2020-06-17T14:11:14Z DEBUG stdout= 2020-06-17T14:11:14Z DEBUG stderr= 2020-06-17T14:11:14Z DEBUG Restart of dirsrv@LIN-TEST-LAN.service complete 2020-06-17T14:11:14Z DEBUG Created connection context.ldap2_140184533109784 2020-06-17T14:11:14Z DEBUG step duration: smb __restart_dirsrv 5.28 sec 2020-06-17T14:11:14Z DEBUG [19/24]: adding fallback group 2020-06-17T14:11:14Z DEBUG Fallback group already set, nothing to do 2020-06-17T14:11:14Z DEBUG step duration: smb __add_fallback_group 0.00 sec 2020-06-17T14:11:14Z DEBUG [20/24]: adding Default Trust View 2020-06-17T14:11:14Z DEBUG Default Trust View already exists. 2020-06-17T14:11:14Z DEBUG step duration: smb __add_default_trust_view 0.00 sec 2020-06-17T14:11:14Z DEBUG [21/24]: setting SELinux booleans 2020-06-17T14:11:14Z DEBUG Starting external process 2020-06-17T14:11:14Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T14:11:14Z DEBUG Process finished, return code=0 2020-06-17T14:11:14Z DEBUG stdout= 2020-06-17T14:11:14Z DEBUG stderr= 2020-06-17T14:11:14Z DEBUG Starting external process 2020-06-17T14:11:14Z DEBUG args=['/usr/sbin/getsebool', 'samba_portmapper'] 2020-06-17T14:11:14Z DEBUG Process finished, return code=0 2020-06-17T14:11:14Z DEBUG stdout=samba_portmapper --> on 2020-06-17T14:11:14Z DEBUG stderr= 2020-06-17T14:11:14Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:11:14Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:11:14Z DEBUG step duration: smb __configure_selinux_for_smbd 0.02 sec 2020-06-17T14:11:14Z DEBUG [22/24]: starting CIFS services 2020-06-17T14:11:14Z DEBUG Starting external process 2020-06-17T14:11:14Z DEBUG args=['/bin/systemctl', 'start', 'smb.service'] 2020-06-17T14:11:15Z DEBUG Process finished, return code=0 2020-06-17T14:11:15Z DEBUG stdout= 2020-06-17T14:11:15Z DEBUG stderr= 2020-06-17T14:11:15Z DEBUG Starting external process 2020-06-17T14:11:15Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T14:11:15Z DEBUG Process finished, return code=0 2020-06-17T14:11:15Z DEBUG stdout=active 2020-06-17T14:11:15Z DEBUG stderr= 2020-06-17T14:11:15Z DEBUG Start of smb.service complete 2020-06-17T14:11:15Z DEBUG Starting external process 2020-06-17T14:11:15Z DEBUG args=['/bin/systemctl', 'start', 'winbind.service'] 2020-06-17T14:11:15Z DEBUG Process finished, return code=0 2020-06-17T14:11:15Z DEBUG stdout= 2020-06-17T14:11:15Z DEBUG stderr= 2020-06-17T14:11:15Z DEBUG Starting external process 2020-06-17T14:11:15Z DEBUG args=['/bin/systemctl', 'is-active', 'winbind.service'] 2020-06-17T14:11:15Z DEBUG Process finished, return code=0 2020-06-17T14:11:15Z DEBUG stdout=active 2020-06-17T14:11:15Z DEBUG stderr= 2020-06-17T14:11:15Z DEBUG Start of winbind.service complete 2020-06-17T14:11:15Z DEBUG step duration: smb __start 0.75 sec 2020-06-17T14:11:15Z DEBUG [23/24]: adding SIDs to existing users and groups 2020-06-17T14:11:15Z DEBUG Starting external process 2020-06-17T14:11:15Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpl6gh41bi', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T14:11:15Z DEBUG Process finished, return code=0 2020-06-17T14:11:15Z DEBUG stdout=add objectClass: top extensibleObject add cn: sidgen add nsslapd-basedn: dc=lin,dc=test,dc=lan add delay: 0 adding new entry "cn=sidgen,cn=ipa-sidgen-task,cn=tasks,cn=config" modify complete 2020-06-17T14:11:15Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T14:11:15Z DEBUG This step may take considerable amount of time, please wait.. 2020-06-17T14:11:16Z DEBUG step duration: smb __add_sids 1.02 sec 2020-06-17T14:11:16Z DEBUG [24/24]: restarting smbd 2020-06-17T14:11:16Z DEBUG step duration: smb __restart_smb 0.00 sec 2020-06-17T14:11:16Z DEBUG Done configuring CIFS. 2020-06-17T14:11:16Z DEBUG service duration: smb 7.81 sec 2020-06-17T14:11:16Z DEBUG raw: update_host_cifs_keytabs 2020-06-17T14:11:16Z DEBUG raw: adtrust_is_enabled(version='2.235') 2020-06-17T14:11:16Z DEBUG adtrust_is_enabled(version='2.235') 2020-06-17T14:11:16Z DEBUG Starting external process 2020-06-17T14:11:16Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/krb5.keytab'] 2020-06-17T14:11:16Z DEBUG Process finished, return code=0 2020-06-17T14:11:16Z DEBUG stdout= 2020-06-17T14:11:16Z DEBUG stderr= 2020-06-17T14:11:16Z DEBUG Starting external process 2020-06-17T14:11:16Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/samba/samba.keytab'] 2020-06-17T14:11:16Z DEBUG Process finished, return code=0 2020-06-17T14:11:16Z DEBUG stdout= 2020-06-17T14:11:16Z DEBUG stderr= 2020-06-17T14:11:16Z DEBUG Starting external process 2020-06-17T14:11:16Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T14:11:16Z DEBUG Process finished, return code=0 2020-06-17T14:11:16Z DEBUG stdout= 2020-06-17T14:11:16Z DEBUG stderr= 2020-06-17T14:11:16Z DEBUG Starting external process 2020-06-17T14:11:16Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T14:11:16Z DEBUG Process finished, return code=0 2020-06-17T14:11:16Z DEBUG stdout= 2020-06-17T14:11:16Z DEBUG stderr= 2020-06-17T14:11:16Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', version='2.235') 2020-06-17T14:11:16Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', include_master=False, all=False, raw=False, version='2.235') 2020-06-17T14:11:16Z DEBUG Set service ['ADTRUST'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T14:11:16Z DEBUG Set service ['EXTID'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T14:11:16Z DEBUG raw: dns_is_enabled(version='2.235') 2020-06-17T14:11:16Z DEBUG dns_is_enabled(version='2.235') 2020-06-17T14:11:16Z DEBUG raw: dnszone_show('lin.test.lan', version='2.235') 2020-06-17T14:11:16Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T14:11:16Z DEBUG raw: dns_update_system_records(version='2.235') 2020-06-17T14:11:16Z DEBUG dns_update_system_records(dry_run=False, all=False, raw=False, version='2.235') 2020-06-17T14:11:16Z DEBUG raw: server_find(None, version='2.235', no_members=False, servrole='IPA master') 2020-06-17T14:11:16Z DEBUG server_find(None, all=False, raw=False, version='2.235', no_members=False, pkey_only=False, servrole=('IPA master',)) 2020-06-17T14:11:16Z DEBUG raw: server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, version='2.235') 2020-06-17T14:11:16Z DEBUG server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T14:11:16Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version='2.235') 2020-06-17T14:11:16Z DEBUG topologysuffix_find(None, all=True, raw=True, version='2.235', pkey_only=False) 2020-06-17T14:11:16Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, version='2.235') 2020-06-17T14:11:16Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T14:11:16Z DEBUG raw: dnszone_show(, version='2.235') 2020-06-17T14:11:16Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T14:11:16Z DEBUG found 1 1 records for freeipaserver.lin.test.lan.: 10.0.0.179 2020-06-17T14:11:16Z DEBUG The DNS response does not contain an answer to the question: freeipaserver.lin.test.lan. IN AAAA 2020-06-17T14:11:16Z DEBUG raw: dnsrecord_mod(, , txtrecord=['"LIN.TEST.LAN"'], version='2.235') 2020-06-17T14:11:16Z DEBUG dnsrecord_mod(, , txtrecord=('"LIN.TEST.LAN"',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:11:16Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:11:16Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:11:16Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:11:16Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:11:16Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:11:16Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:11:16Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:11:16Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:11:16Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:11:16Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:11:16Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:11:16Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:11:16Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:11:16Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:11:16Z DEBUG raw: dnsrecord_mod(, , arecord=['10.0.0.179'], version='2.235') 2020-06-17T14:11:16Z DEBUG dnsrecord_mod(, , arecord=('10.0.0.179',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:11:16Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:11:16Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:11:16Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:11:16Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:11:16Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:11:16Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:11:16Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:11:16Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:11:16Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:11:16Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:11:16Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:11:16Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:11:16Z DEBUG raw: location_find(None, version='2.235') 2020-06-17T14:11:16Z DEBUG location_find(None, all=False, raw=False, version='2.235', pkey_only=False) 2020-06-17T14:11:16Z DEBUG Starting external process 2020-06-17T14:11:16Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T14:11:17Z DEBUG Process finished, return code=0 2020-06-17T14:11:17Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T14:11:17Z DEBUG stderr= 2020-06-17T14:11:17Z DEBUG Destroyed connection context.ldap2_140184533109784 2020-06-17T14:11:17Z INFO The ipa-adtrust-install command was successful 2020-06-17T14:12:59Z DEBUG /usr/sbin/ipa-adtrust-install was invoked with options: {'debug': False, 'netbios_name': 'LIN', 'no_msdcs': False, 'rid_base': 1000, 'secondary_rid_base': 100000000, 'unattended': True, 'add_sids': True, 'add_agents': False, 'enable_compat': False} 2020-06-17T14:12:59Z DEBUG missing options might be asked for interactively later 2020-06-17T14:12:59Z DEBUG IPA version 4.8.4-7.module_el8.2.0+374+0d2d74a1 2020-06-17T14:12:59Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T14:12:59Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T14:12:59Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.aci 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.automember 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.automount 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-06-17T14:12:59Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.batch 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.ca 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.cert 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.config 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.dns 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.group 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-06-17T14:12:59Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.host 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.idoverride-admemberof 2020-06-17T14:12:59Z DEBUG ipaserver.plugins.idoverride-admemberof is not a valid plugin module 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.internal 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.join 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.location 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.migration 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.misc 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.otp 2020-06-17T14:12:59Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.permission 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.ping 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-06-17T14:12:59Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.role 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.schema 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.server 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.service 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.session 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-06-17T14:12:59Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.topology 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.trust 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.user 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.vault 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-06-17T14:12:59Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-06-17T14:12:59Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-06-17T14:13:00Z DEBUG Starting external process 2020-06-17T14:13:00Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T14:13:01Z DEBUG Process finished, return code=0 2020-06-17T14:13:01Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T14:13:01Z DEBUG stderr= 2020-06-17T14:13:01Z DEBUG Created connection context.ldap2_139676163173176 2020-06-17T14:13:01Z DEBUG raw: user_show('admin', version='2.235') 2020-06-17T14:13:01Z DEBUG user_show('admin', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:13:01Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T14:13:01Z DEBUG raw: group_show('admins', version='2.235') 2020-06-17T14:13:01Z DEBUG group_show('admins', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:13:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:13:01Z DEBUG Configuring CIFS 2020-06-17T14:13:01Z DEBUG [1/24]: validate server hostname 2020-06-17T14:13:01Z DEBUG step duration: smb __validate_server_hostname 0.00 sec 2020-06-17T14:13:01Z DEBUG [2/24]: stopping smbd 2020-06-17T14:13:01Z DEBUG Starting external process 2020-06-17T14:13:01Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T14:13:01Z DEBUG Process finished, return code=0 2020-06-17T14:13:01Z DEBUG stdout=active 2020-06-17T14:13:01Z DEBUG stderr= 2020-06-17T14:13:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:13:01Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:13:01Z DEBUG Starting external process 2020-06-17T14:13:01Z DEBUG args=['/bin/systemctl', 'stop', 'winbind.service'] 2020-06-17T14:13:01Z DEBUG Process finished, return code=0 2020-06-17T14:13:01Z DEBUG stdout= 2020-06-17T14:13:01Z DEBUG stderr= 2020-06-17T14:13:01Z DEBUG Stop of winbind.service complete 2020-06-17T14:13:01Z DEBUG Starting external process 2020-06-17T14:13:01Z DEBUG args=['/bin/systemctl', 'stop', 'smb.service'] 2020-06-17T14:13:01Z DEBUG Process finished, return code=0 2020-06-17T14:13:01Z DEBUG stdout= 2020-06-17T14:13:01Z DEBUG stderr= 2020-06-17T14:13:01Z DEBUG Stop of smb.service complete 2020-06-17T14:13:01Z DEBUG step duration: smb __stop 0.09 sec 2020-06-17T14:13:01Z DEBUG [3/24]: creating samba domain object 2020-06-17T14:13:01Z DEBUG Samba domain object already exists 2020-06-17T14:13:01Z DEBUG step duration: smb __create_samba_domain_object 0.00 sec 2020-06-17T14:13:01Z DEBUG [4/24]: retrieve local idmap range 2020-06-17T14:13:01Z DEBUG raw: idrange_show('LIN.TEST.LAN_id_range', version='2.235') 2020-06-17T14:13:01Z DEBUG idrange_show('LIN.TEST.LAN_id_range', rights=False, all=False, raw=False, version='2.235') 2020-06-17T14:13:01Z DEBUG step duration: smb __retrieve_local_range 0.00 sec 2020-06-17T14:13:01Z DEBUG [5/24]: creating samba config registry 2020-06-17T14:13:01Z DEBUG Starting external process 2020-06-17T14:13:01Z DEBUG args=['/usr/bin/net', 'conf', 'import', '/tmp/tmpxadz1b_l'] 2020-06-17T14:13:01Z DEBUG Process finished, return code=0 2020-06-17T14:13:01Z DEBUG stdout= 2020-06-17T14:13:01Z DEBUG stderr= 2020-06-17T14:13:01Z DEBUG step duration: smb __write_smb_registry 0.09 sec 2020-06-17T14:13:01Z DEBUG [6/24]: writing samba config file 2020-06-17T14:13:01Z DEBUG step duration: smb __write_smb_conf 0.00 sec 2020-06-17T14:13:01Z DEBUG [7/24]: adding cifs Kerberos principal 2020-06-17T14:13:01Z DEBUG raw: service_add('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', force=True, version='2.235') 2020-06-17T14:13:01Z DEBUG service_add(ipapython.kerberos.Principal('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN'), force=True, skip_host_check=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:13:01Z DEBUG raw: host_show('freeipaserver.lin.test.lan', version='2.235') 2020-06-17T14:13:01Z DEBUG host_show('freeipaserver.lin.test.lan', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:13:01Z DEBUG Starting external process 2020-06-17T14:13:01Z DEBUG args=['/usr/sbin/ipa-rmkeytab', '--principal', 'cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-k', '/etc/samba/samba.keytab'] 2020-06-17T14:13:01Z DEBUG Process finished, return code=0 2020-06-17T14:13:01Z DEBUG stdout= 2020-06-17T14:13:01Z DEBUG stderr=Suppression du principal cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN 2020-06-17T14:13:01Z DEBUG Removing service credentials cache 2020-06-17T14:13:01Z DEBUG Ccache path: '/var/run/samba/krb5cc_samba' 2020-06-17T14:13:01Z DEBUG Starting external process 2020-06-17T14:13:01Z DEBUG args=['/usr/bin/kdestroy', '-c', '/var/run/samba/krb5cc_samba'] 2020-06-17T14:13:01Z DEBUG Process finished, return code=0 2020-06-17T14:13:01Z DEBUG stdout= 2020-06-17T14:13:01Z DEBUG stderr= 2020-06-17T14:13:01Z DEBUG Starting external process 2020-06-17T14:13:01Z DEBUG args=['/usr/sbin/ipa-getkeytab', '-k', '/etc/samba/samba.keytab', '-p', 'cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T14:13:01Z DEBUG Process finished, return code=0 2020-06-17T14:13:01Z DEBUG stdout= 2020-06-17T14:13:01Z DEBUG stderr=Récupération du tableau de clés et stockage avec succès dans : /etc/samba/samba.keytab 2020-06-17T14:13:01Z DEBUG step duration: smb request_service_keytab 0.07 sec 2020-06-17T14:13:01Z DEBUG [8/24]: adding cifs and host Kerberos principals to the adtrust agents group 2020-06-17T14:13:01Z DEBUG step duration: smb __setup_group_membership 0.00 sec 2020-06-17T14:13:01Z DEBUG [9/24]: check for cifs services defined on other replicas 2020-06-17T14:13:01Z DEBUG step duration: smb __check_replica 0.00 sec 2020-06-17T14:13:01Z DEBUG [10/24]: adding cifs principal to S4U2Proxy targets 2020-06-17T14:13:01Z DEBUG cifs principal already targeted, nothing to do. 2020-06-17T14:13:01Z DEBUG step duration: smb __add_s4u2proxy_target 0.00 sec 2020-06-17T14:13:01Z DEBUG [11/24]: adding admin(group) SIDs 2020-06-17T14:13:01Z DEBUG Admin SID already set, nothing to do 2020-06-17T14:13:01Z DEBUG Admin group SID already set, nothing to do 2020-06-17T14:13:01Z DEBUG step duration: smb __add_admin_sids 0.00 sec 2020-06-17T14:13:01Z DEBUG [12/24]: adding RID bases 2020-06-17T14:13:01Z DEBUG RID bases already set, nothing to do 2020-06-17T14:13:01Z DEBUG step duration: smb __add_rid_bases 0.00 sec 2020-06-17T14:13:01Z DEBUG [13/24]: updating Kerberos config 2020-06-17T14:13:01Z DEBUG 'dns_lookup_kdc' already set to 'true', nothing to do. 2020-06-17T14:13:01Z DEBUG step duration: smb __update_krb5_conf 0.00 sec 2020-06-17T14:13:01Z DEBUG [14/24]: activating CLDAP plugin 2020-06-17T14:13:01Z DEBUG CLDAP plugin already configured, nothing to do 2020-06-17T14:13:01Z DEBUG step duration: smb __add_cldap_module 0.00 sec 2020-06-17T14:13:01Z DEBUG [15/24]: activating sidgen task 2020-06-17T14:13:01Z DEBUG Sidgen task plugin already configured, nothing to do 2020-06-17T14:13:01Z DEBUG step duration: smb __add_sidgen_task 0.00 sec 2020-06-17T14:13:01Z DEBUG [16/24]: map BUILTIN\Guests to nobody group 2020-06-17T14:13:01Z DEBUG Map BUILTIN\Guests to a group 'nobody' 2020-06-17T14:13:01Z DEBUG Starting external process 2020-06-17T14:13:01Z DEBUG args=['/usr/bin/net', '-s', '/dev/null', 'groupmap', 'add', 'sid=S-1-5-32-546', 'unixgroup=nobody', 'type=builtin'] 2020-06-17T14:13:01Z DEBUG Process finished, return code=255 2020-06-17T14:13:01Z DEBUG stdout=Unix group nobody already mapped to SID S-1-5-32-546 2020-06-17T14:13:01Z DEBUG stderr= 2020-06-17T14:13:01Z DEBUG step duration: smb __map_Guests_to_nobody 0.07 sec 2020-06-17T14:13:01Z DEBUG [17/24]: configuring smbd to start on boot 2020-06-17T14:13:01Z DEBUG Starting external process 2020-06-17T14:13:01Z DEBUG args=['/bin/systemctl', 'is-enabled', 'smb.service'] 2020-06-17T14:13:01Z DEBUG Process finished, return code=0 2020-06-17T14:13:01Z DEBUG stdout=enabled 2020-06-17T14:13:01Z DEBUG stderr= 2020-06-17T14:13:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:13:01Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:13:01Z DEBUG Starting external process 2020-06-17T14:13:01Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T14:13:01Z DEBUG Process finished, return code=0 2020-06-17T14:13:01Z DEBUG stdout= 2020-06-17T14:13:01Z DEBUG stderr=Removed /etc/systemd/system/multi-user.target.wants/smb.service. 2020-06-17T14:13:01Z DEBUG service ADTRUST has all config values set 2020-06-17T14:13:01Z DEBUG Starting external process 2020-06-17T14:13:01Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T14:13:02Z DEBUG Process finished, return code=0 2020-06-17T14:13:02Z DEBUG stdout= 2020-06-17T14:13:02Z DEBUG stderr= 2020-06-17T14:13:02Z DEBUG service EXTID has all config values set 2020-06-17T14:13:02Z DEBUG step duration: smb __enable 0.39 sec 2020-06-17T14:13:02Z DEBUG [18/24]: restarting Directory Server to take MS PAC and LDAP plugins changes into account 2020-06-17T14:13:02Z DEBUG Destroyed connection context.ldap2_139676163173176 2020-06-17T14:13:02Z DEBUG Starting external process 2020-06-17T14:13:02Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T14:13:07Z DEBUG Process finished, return code=0 2020-06-17T14:13:07Z DEBUG stdout= 2020-06-17T14:13:07Z DEBUG stderr= 2020-06-17T14:13:07Z DEBUG Restart of dirsrv@LIN-TEST-LAN.service complete 2020-06-17T14:13:07Z DEBUG Created connection context.ldap2_139676163173176 2020-06-17T14:13:07Z DEBUG step duration: smb __restart_dirsrv 4.96 sec 2020-06-17T14:13:07Z DEBUG [19/24]: adding fallback group 2020-06-17T14:13:07Z DEBUG Fallback group already set, nothing to do 2020-06-17T14:13:07Z DEBUG step duration: smb __add_fallback_group 0.00 sec 2020-06-17T14:13:07Z DEBUG [20/24]: adding Default Trust View 2020-06-17T14:13:07Z DEBUG Default Trust View already exists. 2020-06-17T14:13:07Z DEBUG step duration: smb __add_default_trust_view 0.00 sec 2020-06-17T14:13:07Z DEBUG [21/24]: setting SELinux booleans 2020-06-17T14:13:07Z DEBUG Starting external process 2020-06-17T14:13:07Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T14:13:07Z DEBUG Process finished, return code=0 2020-06-17T14:13:07Z DEBUG stdout= 2020-06-17T14:13:07Z DEBUG stderr= 2020-06-17T14:13:07Z DEBUG Starting external process 2020-06-17T14:13:07Z DEBUG args=['/usr/sbin/getsebool', 'samba_portmapper'] 2020-06-17T14:13:07Z DEBUG Process finished, return code=0 2020-06-17T14:13:07Z DEBUG stdout=samba_portmapper --> on 2020-06-17T14:13:07Z DEBUG stderr= 2020-06-17T14:13:07Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:13:07Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:13:07Z DEBUG step duration: smb __configure_selinux_for_smbd 0.01 sec 2020-06-17T14:13:07Z DEBUG [22/24]: starting CIFS services 2020-06-17T14:13:07Z DEBUG Starting external process 2020-06-17T14:13:07Z DEBUG args=['/bin/systemctl', 'start', 'smb.service'] 2020-06-17T14:13:07Z DEBUG Process finished, return code=0 2020-06-17T14:13:07Z DEBUG stdout= 2020-06-17T14:13:07Z DEBUG stderr= 2020-06-17T14:13:07Z DEBUG Starting external process 2020-06-17T14:13:07Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T14:13:07Z DEBUG Process finished, return code=0 2020-06-17T14:13:07Z DEBUG stdout=active 2020-06-17T14:13:07Z DEBUG stderr= 2020-06-17T14:13:07Z DEBUG Start of smb.service complete 2020-06-17T14:13:07Z DEBUG Starting external process 2020-06-17T14:13:07Z DEBUG args=['/bin/systemctl', 'start', 'winbind.service'] 2020-06-17T14:13:07Z DEBUG Process finished, return code=0 2020-06-17T14:13:07Z DEBUG stdout= 2020-06-17T14:13:07Z DEBUG stderr= 2020-06-17T14:13:07Z DEBUG Starting external process 2020-06-17T14:13:07Z DEBUG args=['/bin/systemctl', 'is-active', 'winbind.service'] 2020-06-17T14:13:07Z DEBUG Process finished, return code=0 2020-06-17T14:13:07Z DEBUG stdout=active 2020-06-17T14:13:07Z DEBUG stderr= 2020-06-17T14:13:07Z DEBUG Start of winbind.service complete 2020-06-17T14:13:07Z DEBUG step duration: smb __start 0.74 sec 2020-06-17T14:13:07Z DEBUG [23/24]: adding SIDs to existing users and groups 2020-06-17T14:13:07Z DEBUG Starting external process 2020-06-17T14:13:07Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp4igrqelu', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T14:13:07Z DEBUG Process finished, return code=0 2020-06-17T14:13:07Z DEBUG stdout=add objectClass: top extensibleObject add cn: sidgen add nsslapd-basedn: dc=lin,dc=test,dc=lan add delay: 0 adding new entry "cn=sidgen,cn=ipa-sidgen-task,cn=tasks,cn=config" modify complete 2020-06-17T14:13:07Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T14:13:07Z DEBUG This step may take considerable amount of time, please wait.. 2020-06-17T14:13:08Z DEBUG step duration: smb __add_sids 1.03 sec 2020-06-17T14:13:08Z DEBUG [24/24]: restarting smbd 2020-06-17T14:13:08Z DEBUG step duration: smb __restart_smb 0.00 sec 2020-06-17T14:13:08Z DEBUG Done configuring CIFS. 2020-06-17T14:13:08Z DEBUG service duration: smb 7.47 sec 2020-06-17T14:13:08Z DEBUG raw: update_host_cifs_keytabs 2020-06-17T14:13:08Z DEBUG raw: adtrust_is_enabled(version='2.235') 2020-06-17T14:13:08Z DEBUG adtrust_is_enabled(version='2.235') 2020-06-17T14:13:08Z DEBUG Starting external process 2020-06-17T14:13:08Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/krb5.keytab'] 2020-06-17T14:13:08Z DEBUG Process finished, return code=0 2020-06-17T14:13:08Z DEBUG stdout= 2020-06-17T14:13:08Z DEBUG stderr= 2020-06-17T14:13:08Z DEBUG Starting external process 2020-06-17T14:13:08Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/samba/samba.keytab'] 2020-06-17T14:13:08Z DEBUG Process finished, return code=0 2020-06-17T14:13:08Z DEBUG stdout= 2020-06-17T14:13:08Z DEBUG stderr= 2020-06-17T14:13:08Z DEBUG Starting external process 2020-06-17T14:13:08Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T14:13:08Z DEBUG Process finished, return code=0 2020-06-17T14:13:08Z DEBUG stdout= 2020-06-17T14:13:08Z DEBUG stderr= 2020-06-17T14:13:08Z DEBUG Starting external process 2020-06-17T14:13:08Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T14:13:08Z DEBUG Process finished, return code=0 2020-06-17T14:13:08Z DEBUG stdout= 2020-06-17T14:13:08Z DEBUG stderr= 2020-06-17T14:13:08Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', version='2.235') 2020-06-17T14:13:08Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', include_master=False, all=False, raw=False, version='2.235') 2020-06-17T14:13:08Z DEBUG Set service ['ADTRUST'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T14:13:08Z DEBUG Set service ['EXTID'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T14:13:08Z DEBUG raw: dns_is_enabled(version='2.235') 2020-06-17T14:13:08Z DEBUG dns_is_enabled(version='2.235') 2020-06-17T14:13:08Z DEBUG raw: dnszone_show('lin.test.lan', version='2.235') 2020-06-17T14:13:08Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T14:13:08Z DEBUG raw: dns_update_system_records(version='2.235') 2020-06-17T14:13:08Z DEBUG dns_update_system_records(dry_run=False, all=False, raw=False, version='2.235') 2020-06-17T14:13:08Z DEBUG raw: server_find(None, version='2.235', no_members=False, servrole='IPA master') 2020-06-17T14:13:08Z DEBUG server_find(None, all=False, raw=False, version='2.235', no_members=False, pkey_only=False, servrole=('IPA master',)) 2020-06-17T14:13:08Z DEBUG raw: server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, version='2.235') 2020-06-17T14:13:08Z DEBUG server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T14:13:08Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version='2.235') 2020-06-17T14:13:08Z DEBUG topologysuffix_find(None, all=True, raw=True, version='2.235', pkey_only=False) 2020-06-17T14:13:08Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, version='2.235') 2020-06-17T14:13:08Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T14:13:08Z DEBUG raw: dnszone_show(, version='2.235') 2020-06-17T14:13:08Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T14:13:08Z DEBUG found 1 1 records for freeipaserver.lin.test.lan.: 10.0.0.179 2020-06-17T14:13:08Z DEBUG The DNS response does not contain an answer to the question: freeipaserver.lin.test.lan. IN AAAA 2020-06-17T14:13:08Z DEBUG raw: dnsrecord_mod(, , txtrecord=['"LIN.TEST.LAN"'], version='2.235') 2020-06-17T14:13:08Z DEBUG dnsrecord_mod(, , txtrecord=('"LIN.TEST.LAN"',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:13:08Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:13:08Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:13:08Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:13:08Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:13:08Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:13:08Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:13:08Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:13:08Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:13:08Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:13:08Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:13:08Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:13:08Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:13:08Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:13:08Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:13:08Z DEBUG raw: dnsrecord_mod(, , arecord=['10.0.0.179'], version='2.235') 2020-06-17T14:13:08Z DEBUG dnsrecord_mod(, , arecord=('10.0.0.179',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:13:08Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:13:08Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:13:08Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:13:08Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:13:08Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:13:08Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:13:08Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:13:08Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:13:09Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:13:09Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:13:09Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:13:09Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:13:09Z DEBUG raw: location_find(None, version='2.235') 2020-06-17T14:13:09Z DEBUG location_find(None, all=False, raw=False, version='2.235', pkey_only=False) 2020-06-17T14:13:09Z DEBUG Starting external process 2020-06-17T14:13:09Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T14:13:09Z DEBUG Process finished, return code=0 2020-06-17T14:13:09Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T14:13:09Z DEBUG stderr= 2020-06-17T14:13:09Z DEBUG Destroyed connection context.ldap2_139676163173176 2020-06-17T14:13:09Z INFO The ipa-adtrust-install command was successful 2020-06-17T14:14:36Z DEBUG /usr/sbin/ipa-adtrust-install was invoked with options: {'debug': False, 'netbios_name': 'LIN', 'no_msdcs': False, 'rid_base': 1000, 'secondary_rid_base': 100000000, 'unattended': True, 'add_sids': True, 'add_agents': False, 'enable_compat': False} 2020-06-17T14:14:36Z DEBUG missing options might be asked for interactively later 2020-06-17T14:14:36Z DEBUG IPA version 4.8.4-7.module_el8.2.0+374+0d2d74a1 2020-06-17T14:14:36Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T14:14:36Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T14:14:36Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.aci 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.automember 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.automount 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-06-17T14:14:36Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.batch 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.ca 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.cert 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.config 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.dns 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.group 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-06-17T14:14:36Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.host 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.idoverride-admemberof 2020-06-17T14:14:36Z DEBUG ipaserver.plugins.idoverride-admemberof is not a valid plugin module 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.internal 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.join 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.location 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.migration 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.misc 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.otp 2020-06-17T14:14:36Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.permission 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.ping 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-06-17T14:14:36Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.role 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.schema 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-06-17T14:14:36Z DEBUG importing plugin module ipaserver.plugins.server 2020-06-17T14:14:37Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-06-17T14:14:37Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-06-17T14:14:37Z DEBUG importing plugin module ipaserver.plugins.service 2020-06-17T14:14:37Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-06-17T14:14:37Z DEBUG importing plugin module ipaserver.plugins.session 2020-06-17T14:14:37Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-06-17T14:14:37Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-06-17T14:14:37Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-06-17T14:14:37Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-06-17T14:14:37Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-06-17T14:14:37Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-06-17T14:14:37Z DEBUG importing plugin module ipaserver.plugins.topology 2020-06-17T14:14:37Z DEBUG importing plugin module ipaserver.plugins.trust 2020-06-17T14:14:37Z DEBUG importing plugin module ipaserver.plugins.user 2020-06-17T14:14:37Z DEBUG importing plugin module ipaserver.plugins.vault 2020-06-17T14:14:37Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-06-17T14:14:37Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-06-17T14:14:37Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-06-17T14:14:37Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-06-17T14:14:38Z DEBUG Starting external process 2020-06-17T14:14:38Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T14:14:38Z DEBUG Process finished, return code=0 2020-06-17T14:14:38Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T14:14:38Z DEBUG stderr= 2020-06-17T14:14:38Z DEBUG Created connection context.ldap2_140455511792440 2020-06-17T14:14:38Z DEBUG raw: user_show('admin', version='2.235') 2020-06-17T14:14:38Z DEBUG user_show('admin', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:14:38Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T14:14:39Z DEBUG raw: group_show('admins', version='2.235') 2020-06-17T14:14:39Z DEBUG group_show('admins', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:14:39Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:14:39Z DEBUG Configuring CIFS 2020-06-17T14:14:39Z DEBUG [1/24]: validate server hostname 2020-06-17T14:14:39Z DEBUG step duration: smb __validate_server_hostname 0.00 sec 2020-06-17T14:14:39Z DEBUG [2/24]: stopping smbd 2020-06-17T14:14:39Z DEBUG Starting external process 2020-06-17T14:14:39Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T14:14:39Z DEBUG Process finished, return code=0 2020-06-17T14:14:39Z DEBUG stdout=active 2020-06-17T14:14:39Z DEBUG stderr= 2020-06-17T14:14:39Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:14:39Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:14:39Z DEBUG Starting external process 2020-06-17T14:14:39Z DEBUG args=['/bin/systemctl', 'stop', 'winbind.service'] 2020-06-17T14:14:39Z DEBUG Process finished, return code=0 2020-06-17T14:14:39Z DEBUG stdout= 2020-06-17T14:14:39Z DEBUG stderr= 2020-06-17T14:14:39Z DEBUG Stop of winbind.service complete 2020-06-17T14:14:39Z DEBUG Starting external process 2020-06-17T14:14:39Z DEBUG args=['/bin/systemctl', 'stop', 'smb.service'] 2020-06-17T14:14:39Z DEBUG Process finished, return code=0 2020-06-17T14:14:39Z DEBUG stdout= 2020-06-17T14:14:39Z DEBUG stderr= 2020-06-17T14:14:39Z DEBUG Stop of smb.service complete 2020-06-17T14:14:39Z DEBUG step duration: smb __stop 0.08 sec 2020-06-17T14:14:39Z DEBUG [3/24]: creating samba domain object 2020-06-17T14:14:39Z DEBUG Samba domain object already exists 2020-06-17T14:14:39Z DEBUG step duration: smb __create_samba_domain_object 0.00 sec 2020-06-17T14:14:39Z DEBUG [4/24]: retrieve local idmap range 2020-06-17T14:14:39Z DEBUG raw: idrange_show('LIN.TEST.LAN_id_range', version='2.235') 2020-06-17T14:14:39Z DEBUG idrange_show('LIN.TEST.LAN_id_range', rights=False, all=False, raw=False, version='2.235') 2020-06-17T14:14:39Z DEBUG step duration: smb __retrieve_local_range 0.00 sec 2020-06-17T14:14:39Z DEBUG [5/24]: creating samba config registry 2020-06-17T14:14:39Z DEBUG Starting external process 2020-06-17T14:14:39Z DEBUG args=['/usr/bin/net', 'conf', 'import', '/tmp/tmpv6uh7mdn'] 2020-06-17T14:14:39Z DEBUG Process finished, return code=0 2020-06-17T14:14:39Z DEBUG stdout= 2020-06-17T14:14:39Z DEBUG stderr= 2020-06-17T14:14:39Z DEBUG step duration: smb __write_smb_registry 0.11 sec 2020-06-17T14:14:39Z DEBUG [6/24]: writing samba config file 2020-06-17T14:14:39Z DEBUG step duration: smb __write_smb_conf 0.00 sec 2020-06-17T14:14:39Z DEBUG [7/24]: adding cifs Kerberos principal 2020-06-17T14:14:39Z DEBUG raw: service_add('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', force=True, version='2.235') 2020-06-17T14:14:39Z DEBUG service_add(ipapython.kerberos.Principal('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN'), force=True, skip_host_check=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:14:39Z DEBUG raw: host_show('freeipaserver.lin.test.lan', version='2.235') 2020-06-17T14:14:39Z DEBUG host_show('freeipaserver.lin.test.lan', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:14:39Z DEBUG Starting external process 2020-06-17T14:14:39Z DEBUG args=['/usr/sbin/ipa-rmkeytab', '--principal', 'cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-k', '/etc/samba/samba.keytab'] 2020-06-17T14:14:39Z DEBUG Process finished, return code=0 2020-06-17T14:14:39Z DEBUG stdout= 2020-06-17T14:14:39Z DEBUG stderr=Suppression du principal cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN 2020-06-17T14:14:39Z DEBUG Removing service credentials cache 2020-06-17T14:14:39Z DEBUG Ccache path: '/var/run/samba/krb5cc_samba' 2020-06-17T14:14:39Z DEBUG Starting external process 2020-06-17T14:14:39Z DEBUG args=['/usr/bin/kdestroy', '-c', '/var/run/samba/krb5cc_samba'] 2020-06-17T14:14:39Z DEBUG Process finished, return code=0 2020-06-17T14:14:39Z DEBUG stdout= 2020-06-17T14:14:39Z DEBUG stderr= 2020-06-17T14:14:39Z DEBUG Starting external process 2020-06-17T14:14:39Z DEBUG args=['/usr/sbin/ipa-getkeytab', '-k', '/etc/samba/samba.keytab', '-p', 'cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T14:14:39Z DEBUG Process finished, return code=0 2020-06-17T14:14:39Z DEBUG stdout= 2020-06-17T14:14:39Z DEBUG stderr=Récupération du tableau de clés et stockage avec succès dans : /etc/samba/samba.keytab 2020-06-17T14:14:39Z DEBUG step duration: smb request_service_keytab 0.07 sec 2020-06-17T14:14:39Z DEBUG [8/24]: adding cifs and host Kerberos principals to the adtrust agents group 2020-06-17T14:14:39Z DEBUG step duration: smb __setup_group_membership 0.00 sec 2020-06-17T14:14:39Z DEBUG [9/24]: check for cifs services defined on other replicas 2020-06-17T14:14:39Z DEBUG step duration: smb __check_replica 0.00 sec 2020-06-17T14:14:39Z DEBUG [10/24]: adding cifs principal to S4U2Proxy targets 2020-06-17T14:14:39Z DEBUG cifs principal already targeted, nothing to do. 2020-06-17T14:14:39Z DEBUG step duration: smb __add_s4u2proxy_target 0.00 sec 2020-06-17T14:14:39Z DEBUG [11/24]: adding admin(group) SIDs 2020-06-17T14:14:39Z DEBUG Admin SID already set, nothing to do 2020-06-17T14:14:39Z DEBUG Admin group SID already set, nothing to do 2020-06-17T14:14:39Z DEBUG step duration: smb __add_admin_sids 0.00 sec 2020-06-17T14:14:39Z DEBUG [12/24]: adding RID bases 2020-06-17T14:14:39Z DEBUG RID bases already set, nothing to do 2020-06-17T14:14:39Z DEBUG step duration: smb __add_rid_bases 0.00 sec 2020-06-17T14:14:39Z DEBUG [13/24]: updating Kerberos config 2020-06-17T14:14:39Z DEBUG 'dns_lookup_kdc' already set to 'true', nothing to do. 2020-06-17T14:14:39Z DEBUG step duration: smb __update_krb5_conf 0.00 sec 2020-06-17T14:14:39Z DEBUG [14/24]: activating CLDAP plugin 2020-06-17T14:14:39Z DEBUG CLDAP plugin already configured, nothing to do 2020-06-17T14:14:39Z DEBUG step duration: smb __add_cldap_module 0.00 sec 2020-06-17T14:14:39Z DEBUG [15/24]: activating sidgen task 2020-06-17T14:14:39Z DEBUG Sidgen task plugin already configured, nothing to do 2020-06-17T14:14:39Z DEBUG step duration: smb __add_sidgen_task 0.00 sec 2020-06-17T14:14:39Z DEBUG [16/24]: map BUILTIN\Guests to nobody group 2020-06-17T14:14:39Z DEBUG Map BUILTIN\Guests to a group 'nobody' 2020-06-17T14:14:39Z DEBUG Starting external process 2020-06-17T14:14:39Z DEBUG args=['/usr/bin/net', '-s', '/dev/null', 'groupmap', 'add', 'sid=S-1-5-32-546', 'unixgroup=nobody', 'type=builtin'] 2020-06-17T14:14:39Z DEBUG Process finished, return code=255 2020-06-17T14:14:39Z DEBUG stdout=Unix group nobody already mapped to SID S-1-5-32-546 2020-06-17T14:14:39Z DEBUG stderr= 2020-06-17T14:14:39Z DEBUG step duration: smb __map_Guests_to_nobody 0.08 sec 2020-06-17T14:14:39Z DEBUG [17/24]: configuring smbd to start on boot 2020-06-17T14:14:39Z DEBUG Starting external process 2020-06-17T14:14:39Z DEBUG args=['/bin/systemctl', 'is-enabled', 'smb.service'] 2020-06-17T14:14:39Z DEBUG Process finished, return code=0 2020-06-17T14:14:39Z DEBUG stdout=enabled 2020-06-17T14:14:39Z DEBUG stderr= 2020-06-17T14:14:39Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:14:39Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:14:39Z DEBUG Starting external process 2020-06-17T14:14:39Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T14:14:39Z DEBUG Process finished, return code=0 2020-06-17T14:14:39Z DEBUG stdout= 2020-06-17T14:14:39Z DEBUG stderr=Removed /etc/systemd/system/multi-user.target.wants/smb.service. 2020-06-17T14:14:39Z DEBUG service ADTRUST has all config values set 2020-06-17T14:14:39Z DEBUG Starting external process 2020-06-17T14:14:39Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T14:14:39Z DEBUG Process finished, return code=0 2020-06-17T14:14:39Z DEBUG stdout= 2020-06-17T14:14:39Z DEBUG stderr= 2020-06-17T14:14:39Z DEBUG service EXTID has all config values set 2020-06-17T14:14:39Z DEBUG step duration: smb __enable 0.39 sec 2020-06-17T14:14:39Z DEBUG [18/24]: restarting Directory Server to take MS PAC and LDAP plugins changes into account 2020-06-17T14:14:39Z DEBUG Destroyed connection context.ldap2_140455511792440 2020-06-17T14:14:39Z DEBUG Starting external process 2020-06-17T14:14:39Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T14:14:44Z DEBUG Process finished, return code=0 2020-06-17T14:14:44Z DEBUG stdout= 2020-06-17T14:14:44Z DEBUG stderr= 2020-06-17T14:14:44Z DEBUG Restart of dirsrv@LIN-TEST-LAN.service complete 2020-06-17T14:14:44Z DEBUG Created connection context.ldap2_140455511792440 2020-06-17T14:14:44Z DEBUG step duration: smb __restart_dirsrv 4.44 sec 2020-06-17T14:14:44Z DEBUG [19/24]: adding fallback group 2020-06-17T14:14:44Z DEBUG Fallback group already set, nothing to do 2020-06-17T14:14:44Z DEBUG step duration: smb __add_fallback_group 0.00 sec 2020-06-17T14:14:44Z DEBUG [20/24]: adding Default Trust View 2020-06-17T14:14:44Z DEBUG Default Trust View already exists. 2020-06-17T14:14:44Z DEBUG step duration: smb __add_default_trust_view 0.00 sec 2020-06-17T14:14:44Z DEBUG [21/24]: setting SELinux booleans 2020-06-17T14:14:44Z DEBUG Starting external process 2020-06-17T14:14:44Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T14:14:44Z DEBUG Process finished, return code=0 2020-06-17T14:14:44Z DEBUG stdout= 2020-06-17T14:14:44Z DEBUG stderr= 2020-06-17T14:14:44Z DEBUG Starting external process 2020-06-17T14:14:44Z DEBUG args=['/usr/sbin/getsebool', 'samba_portmapper'] 2020-06-17T14:14:44Z DEBUG Process finished, return code=0 2020-06-17T14:14:44Z DEBUG stdout=samba_portmapper --> on 2020-06-17T14:14:44Z DEBUG stderr= 2020-06-17T14:14:44Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:14:44Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:14:44Z DEBUG step duration: smb __configure_selinux_for_smbd 0.02 sec 2020-06-17T14:14:44Z DEBUG [22/24]: starting CIFS services 2020-06-17T14:14:44Z DEBUG Starting external process 2020-06-17T14:14:44Z DEBUG args=['/bin/systemctl', 'start', 'smb.service'] 2020-06-17T14:14:44Z DEBUG Process finished, return code=0 2020-06-17T14:14:44Z DEBUG stdout= 2020-06-17T14:14:44Z DEBUG stderr= 2020-06-17T14:14:44Z DEBUG Starting external process 2020-06-17T14:14:44Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T14:14:44Z DEBUG Process finished, return code=0 2020-06-17T14:14:44Z DEBUG stdout=active 2020-06-17T14:14:44Z DEBUG stderr= 2020-06-17T14:14:44Z DEBUG Start of smb.service complete 2020-06-17T14:14:44Z DEBUG Starting external process 2020-06-17T14:14:44Z DEBUG args=['/bin/systemctl', 'start', 'winbind.service'] 2020-06-17T14:14:44Z DEBUG Process finished, return code=0 2020-06-17T14:14:44Z DEBUG stdout= 2020-06-17T14:14:44Z DEBUG stderr= 2020-06-17T14:14:44Z DEBUG Starting external process 2020-06-17T14:14:44Z DEBUG args=['/bin/systemctl', 'is-active', 'winbind.service'] 2020-06-17T14:14:44Z DEBUG Process finished, return code=0 2020-06-17T14:14:44Z DEBUG stdout=active 2020-06-17T14:14:44Z DEBUG stderr= 2020-06-17T14:14:44Z DEBUG Start of winbind.service complete 2020-06-17T14:14:44Z DEBUG step duration: smb __start 0.70 sec 2020-06-17T14:14:44Z DEBUG [23/24]: adding SIDs to existing users and groups 2020-06-17T14:14:44Z DEBUG Starting external process 2020-06-17T14:14:44Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp04dhpppk', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T14:14:44Z DEBUG Process finished, return code=0 2020-06-17T14:14:44Z DEBUG stdout=add objectClass: top extensibleObject add cn: sidgen add nsslapd-basedn: dc=lin,dc=test,dc=lan add delay: 0 adding new entry "cn=sidgen,cn=ipa-sidgen-task,cn=tasks,cn=config" modify complete 2020-06-17T14:14:44Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T14:14:44Z DEBUG This step may take considerable amount of time, please wait.. 2020-06-17T14:14:45Z DEBUG step duration: smb __add_sids 1.02 sec 2020-06-17T14:14:45Z DEBUG [24/24]: restarting smbd 2020-06-17T14:14:45Z DEBUG step duration: smb __restart_smb 0.00 sec 2020-06-17T14:14:45Z DEBUG Done configuring CIFS. 2020-06-17T14:14:45Z DEBUG service duration: smb 6.92 sec 2020-06-17T14:14:45Z DEBUG raw: update_host_cifs_keytabs 2020-06-17T14:14:45Z DEBUG raw: adtrust_is_enabled(version='2.235') 2020-06-17T14:14:45Z DEBUG adtrust_is_enabled(version='2.235') 2020-06-17T14:14:45Z DEBUG Starting external process 2020-06-17T14:14:45Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/krb5.keytab'] 2020-06-17T14:14:45Z DEBUG Process finished, return code=0 2020-06-17T14:14:45Z DEBUG stdout= 2020-06-17T14:14:45Z DEBUG stderr= 2020-06-17T14:14:45Z DEBUG Starting external process 2020-06-17T14:14:45Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/samba/samba.keytab'] 2020-06-17T14:14:45Z DEBUG Process finished, return code=0 2020-06-17T14:14:45Z DEBUG stdout= 2020-06-17T14:14:45Z DEBUG stderr= 2020-06-17T14:14:45Z DEBUG Starting external process 2020-06-17T14:14:45Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T14:14:45Z DEBUG Process finished, return code=0 2020-06-17T14:14:45Z DEBUG stdout= 2020-06-17T14:14:45Z DEBUG stderr= 2020-06-17T14:14:45Z DEBUG Starting external process 2020-06-17T14:14:45Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T14:14:45Z DEBUG Process finished, return code=0 2020-06-17T14:14:45Z DEBUG stdout= 2020-06-17T14:14:45Z DEBUG stderr= 2020-06-17T14:14:45Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', version='2.235') 2020-06-17T14:14:45Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', include_master=False, all=False, raw=False, version='2.235') 2020-06-17T14:14:45Z DEBUG Set service ['ADTRUST'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T14:14:45Z DEBUG Set service ['EXTID'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T14:14:45Z DEBUG raw: dns_is_enabled(version='2.235') 2020-06-17T14:14:45Z DEBUG dns_is_enabled(version='2.235') 2020-06-17T14:14:45Z DEBUG raw: dnszone_show('lin.test.lan', version='2.235') 2020-06-17T14:14:45Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T14:14:45Z DEBUG raw: dns_update_system_records(version='2.235') 2020-06-17T14:14:45Z DEBUG dns_update_system_records(dry_run=False, all=False, raw=False, version='2.235') 2020-06-17T14:14:45Z DEBUG raw: server_find(None, version='2.235', no_members=False, servrole='IPA master') 2020-06-17T14:14:45Z DEBUG server_find(None, all=False, raw=False, version='2.235', no_members=False, pkey_only=False, servrole=('IPA master',)) 2020-06-17T14:14:45Z DEBUG raw: server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, version='2.235') 2020-06-17T14:14:45Z DEBUG server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T14:14:45Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version='2.235') 2020-06-17T14:14:45Z DEBUG topologysuffix_find(None, all=True, raw=True, version='2.235', pkey_only=False) 2020-06-17T14:14:45Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, version='2.235') 2020-06-17T14:14:45Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T14:14:45Z DEBUG raw: dnszone_show(, version='2.235') 2020-06-17T14:14:45Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T14:14:46Z DEBUG found 1 1 records for freeipaserver.lin.test.lan.: 10.0.0.179 2020-06-17T14:14:46Z DEBUG The DNS response does not contain an answer to the question: freeipaserver.lin.test.lan. IN AAAA 2020-06-17T14:14:46Z DEBUG raw: dnsrecord_mod(, , txtrecord=['"LIN.TEST.LAN"'], version='2.235') 2020-06-17T14:14:46Z DEBUG dnsrecord_mod(, , txtrecord=('"LIN.TEST.LAN"',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:14:46Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:14:46Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:14:46Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:14:46Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:14:46Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:14:46Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:14:46Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:14:46Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:14:46Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:14:46Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:14:46Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:14:46Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:14:46Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:14:46Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:14:46Z DEBUG raw: dnsrecord_mod(, , arecord=['10.0.0.179'], version='2.235') 2020-06-17T14:14:46Z DEBUG dnsrecord_mod(, , arecord=('10.0.0.179',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:14:46Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:14:46Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:14:46Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:14:46Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:14:46Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:14:46Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:14:46Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:14:46Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:14:46Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:14:46Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:14:46Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:14:46Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:14:46Z DEBUG raw: location_find(None, version='2.235') 2020-06-17T14:14:46Z DEBUG location_find(None, all=False, raw=False, version='2.235', pkey_only=False) 2020-06-17T14:14:46Z DEBUG Starting external process 2020-06-17T14:14:46Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T14:14:46Z DEBUG Process finished, return code=0 2020-06-17T14:14:46Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T14:14:46Z DEBUG stderr= 2020-06-17T14:14:46Z DEBUG Destroyed connection context.ldap2_140455511792440 2020-06-17T14:14:46Z INFO The ipa-adtrust-install command was successful 2020-06-17T14:16:52Z DEBUG /usr/sbin/ipa-adtrust-install was invoked with options: {'debug': False, 'netbios_name': 'LIN', 'no_msdcs': False, 'rid_base': 1000, 'secondary_rid_base': 100000000, 'unattended': True, 'add_sids': True, 'add_agents': False, 'enable_compat': False} 2020-06-17T14:16:52Z DEBUG missing options might be asked for interactively later 2020-06-17T14:16:52Z DEBUG IPA version 4.8.4-7.module_el8.2.0+374+0d2d74a1 2020-06-17T14:16:52Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T14:16:52Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T14:16:52Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-06-17T14:16:52Z DEBUG importing plugin module ipaserver.plugins.aci 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.automember 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.automount 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-06-17T14:16:53Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.batch 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.ca 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.cert 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.config 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.dns 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.group 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-06-17T14:16:53Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.host 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.idoverride-admemberof 2020-06-17T14:16:53Z DEBUG ipaserver.plugins.idoverride-admemberof is not a valid plugin module 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.internal 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.join 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.location 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.migration 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.misc 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.otp 2020-06-17T14:16:53Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.permission 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.ping 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-06-17T14:16:53Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.role 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.schema 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.server 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.service 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.session 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-06-17T14:16:53Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.topology 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.trust 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.user 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.vault 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-06-17T14:16:53Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-06-17T14:16:53Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-06-17T14:16:54Z DEBUG Starting external process 2020-06-17T14:16:54Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T14:16:55Z DEBUG Process finished, return code=0 2020-06-17T14:16:55Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T14:16:55Z DEBUG stderr= 2020-06-17T14:16:55Z DEBUG Created connection context.ldap2_140529472748344 2020-06-17T14:16:55Z DEBUG raw: user_show('admin', version='2.235') 2020-06-17T14:16:55Z DEBUG user_show('admin', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:16:55Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T14:16:55Z DEBUG raw: group_show('admins', version='2.235') 2020-06-17T14:16:55Z DEBUG group_show('admins', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:16:55Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:16:55Z DEBUG Configuring CIFS 2020-06-17T14:16:55Z DEBUG [1/24]: validate server hostname 2020-06-17T14:16:55Z DEBUG step duration: smb __validate_server_hostname 0.00 sec 2020-06-17T14:16:55Z DEBUG [2/24]: stopping smbd 2020-06-17T14:16:55Z DEBUG Starting external process 2020-06-17T14:16:55Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T14:16:55Z DEBUG Process finished, return code=0 2020-06-17T14:16:55Z DEBUG stdout=active 2020-06-17T14:16:55Z DEBUG stderr= 2020-06-17T14:16:55Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:16:55Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:16:55Z DEBUG Starting external process 2020-06-17T14:16:55Z DEBUG args=['/bin/systemctl', 'stop', 'winbind.service'] 2020-06-17T14:16:55Z DEBUG Process finished, return code=0 2020-06-17T14:16:55Z DEBUG stdout= 2020-06-17T14:16:55Z DEBUG stderr= 2020-06-17T14:16:55Z DEBUG Stop of winbind.service complete 2020-06-17T14:16:55Z DEBUG Starting external process 2020-06-17T14:16:55Z DEBUG args=['/bin/systemctl', 'stop', 'smb.service'] 2020-06-17T14:16:55Z DEBUG Process finished, return code=0 2020-06-17T14:16:55Z DEBUG stdout= 2020-06-17T14:16:55Z DEBUG stderr= 2020-06-17T14:16:55Z DEBUG Stop of smb.service complete 2020-06-17T14:16:55Z DEBUG step duration: smb __stop 0.10 sec 2020-06-17T14:16:55Z DEBUG [3/24]: creating samba domain object 2020-06-17T14:16:55Z DEBUG Samba domain object already exists 2020-06-17T14:16:55Z DEBUG step duration: smb __create_samba_domain_object 0.00 sec 2020-06-17T14:16:55Z DEBUG [4/24]: retrieve local idmap range 2020-06-17T14:16:55Z DEBUG raw: idrange_show('LIN.TEST.LAN_id_range', version='2.235') 2020-06-17T14:16:55Z DEBUG idrange_show('LIN.TEST.LAN_id_range', rights=False, all=False, raw=False, version='2.235') 2020-06-17T14:16:55Z DEBUG step duration: smb __retrieve_local_range 0.00 sec 2020-06-17T14:16:55Z DEBUG [5/24]: creating samba config registry 2020-06-17T14:16:55Z DEBUG Starting external process 2020-06-17T14:16:55Z DEBUG args=['/usr/bin/net', 'conf', 'import', '/tmp/tmp3qh9ulmb'] 2020-06-17T14:16:55Z DEBUG Process finished, return code=0 2020-06-17T14:16:55Z DEBUG stdout= 2020-06-17T14:16:55Z DEBUG stderr= 2020-06-17T14:16:55Z DEBUG step duration: smb __write_smb_registry 0.10 sec 2020-06-17T14:16:55Z DEBUG [6/24]: writing samba config file 2020-06-17T14:16:55Z DEBUG step duration: smb __write_smb_conf 0.00 sec 2020-06-17T14:16:55Z DEBUG [7/24]: adding cifs Kerberos principal 2020-06-17T14:16:55Z DEBUG raw: service_add('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', force=True, version='2.235') 2020-06-17T14:16:55Z DEBUG service_add(ipapython.kerberos.Principal('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN'), force=True, skip_host_check=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:16:55Z DEBUG raw: host_show('freeipaserver.lin.test.lan', version='2.235') 2020-06-17T14:16:55Z DEBUG host_show('freeipaserver.lin.test.lan', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:16:55Z DEBUG Starting external process 2020-06-17T14:16:55Z DEBUG args=['/usr/sbin/ipa-rmkeytab', '--principal', 'cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-k', '/etc/samba/samba.keytab'] 2020-06-17T14:16:55Z DEBUG Process finished, return code=0 2020-06-17T14:16:55Z DEBUG stdout= 2020-06-17T14:16:55Z DEBUG stderr=Suppression du principal cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN 2020-06-17T14:16:55Z DEBUG Removing service credentials cache 2020-06-17T14:16:55Z DEBUG Ccache path: '/var/run/samba/krb5cc_samba' 2020-06-17T14:16:55Z DEBUG Starting external process 2020-06-17T14:16:55Z DEBUG args=['/usr/bin/kdestroy', '-c', '/var/run/samba/krb5cc_samba'] 2020-06-17T14:16:55Z DEBUG Process finished, return code=0 2020-06-17T14:16:55Z DEBUG stdout= 2020-06-17T14:16:55Z DEBUG stderr= 2020-06-17T14:16:55Z DEBUG Starting external process 2020-06-17T14:16:55Z DEBUG args=['/usr/sbin/ipa-getkeytab', '-k', '/etc/samba/samba.keytab', '-p', 'cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T14:16:55Z DEBUG Process finished, return code=0 2020-06-17T14:16:55Z DEBUG stdout= 2020-06-17T14:16:55Z DEBUG stderr=Récupération du tableau de clés et stockage avec succès dans : /etc/samba/samba.keytab 2020-06-17T14:16:55Z DEBUG step duration: smb request_service_keytab 0.08 sec 2020-06-17T14:16:55Z DEBUG [8/24]: adding cifs and host Kerberos principals to the adtrust agents group 2020-06-17T14:16:55Z DEBUG step duration: smb __setup_group_membership 0.00 sec 2020-06-17T14:16:55Z DEBUG [9/24]: check for cifs services defined on other replicas 2020-06-17T14:16:55Z DEBUG step duration: smb __check_replica 0.00 sec 2020-06-17T14:16:55Z DEBUG [10/24]: adding cifs principal to S4U2Proxy targets 2020-06-17T14:16:55Z DEBUG cifs principal already targeted, nothing to do. 2020-06-17T14:16:55Z DEBUG step duration: smb __add_s4u2proxy_target 0.00 sec 2020-06-17T14:16:55Z DEBUG [11/24]: adding admin(group) SIDs 2020-06-17T14:16:55Z DEBUG Admin SID already set, nothing to do 2020-06-17T14:16:55Z DEBUG Admin group SID already set, nothing to do 2020-06-17T14:16:55Z DEBUG step duration: smb __add_admin_sids 0.00 sec 2020-06-17T14:16:55Z DEBUG [12/24]: adding RID bases 2020-06-17T14:16:55Z DEBUG RID bases already set, nothing to do 2020-06-17T14:16:55Z DEBUG step duration: smb __add_rid_bases 0.00 sec 2020-06-17T14:16:55Z DEBUG [13/24]: updating Kerberos config 2020-06-17T14:16:55Z DEBUG 'dns_lookup_kdc' already set to 'true', nothing to do. 2020-06-17T14:16:55Z DEBUG step duration: smb __update_krb5_conf 0.00 sec 2020-06-17T14:16:55Z DEBUG [14/24]: activating CLDAP plugin 2020-06-17T14:16:55Z DEBUG CLDAP plugin already configured, nothing to do 2020-06-17T14:16:55Z DEBUG step duration: smb __add_cldap_module 0.00 sec 2020-06-17T14:16:55Z DEBUG [15/24]: activating sidgen task 2020-06-17T14:16:55Z DEBUG Sidgen task plugin already configured, nothing to do 2020-06-17T14:16:55Z DEBUG step duration: smb __add_sidgen_task 0.00 sec 2020-06-17T14:16:55Z DEBUG [16/24]: map BUILTIN\Guests to nobody group 2020-06-17T14:16:55Z DEBUG Map BUILTIN\Guests to a group 'nobody' 2020-06-17T14:16:55Z DEBUG Starting external process 2020-06-17T14:16:55Z DEBUG args=['/usr/bin/net', '-s', '/dev/null', 'groupmap', 'add', 'sid=S-1-5-32-546', 'unixgroup=nobody', 'type=builtin'] 2020-06-17T14:16:55Z DEBUG Process finished, return code=255 2020-06-17T14:16:55Z DEBUG stdout=Unix group nobody already mapped to SID S-1-5-32-546 2020-06-17T14:16:55Z DEBUG stderr= 2020-06-17T14:16:55Z DEBUG step duration: smb __map_Guests_to_nobody 0.07 sec 2020-06-17T14:16:55Z DEBUG [17/24]: configuring smbd to start on boot 2020-06-17T14:16:55Z DEBUG Starting external process 2020-06-17T14:16:55Z DEBUG args=['/bin/systemctl', 'is-enabled', 'smb.service'] 2020-06-17T14:16:55Z DEBUG Process finished, return code=0 2020-06-17T14:16:55Z DEBUG stdout=enabled 2020-06-17T14:16:55Z DEBUG stderr= 2020-06-17T14:16:55Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:16:55Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:16:55Z DEBUG Starting external process 2020-06-17T14:16:55Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T14:16:55Z DEBUG Process finished, return code=0 2020-06-17T14:16:55Z DEBUG stdout= 2020-06-17T14:16:55Z DEBUG stderr=Removed /etc/systemd/system/multi-user.target.wants/smb.service. 2020-06-17T14:16:55Z DEBUG service ADTRUST has all config values set 2020-06-17T14:16:55Z DEBUG Starting external process 2020-06-17T14:16:55Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T14:16:56Z DEBUG Process finished, return code=0 2020-06-17T14:16:56Z DEBUG stdout= 2020-06-17T14:16:56Z DEBUG stderr= 2020-06-17T14:16:56Z DEBUG service EXTID has all config values set 2020-06-17T14:16:56Z DEBUG step duration: smb __enable 0.39 sec 2020-06-17T14:16:56Z DEBUG [18/24]: restarting Directory Server to take MS PAC and LDAP plugins changes into account 2020-06-17T14:16:56Z DEBUG Destroyed connection context.ldap2_140529472748344 2020-06-17T14:16:56Z DEBUG Starting external process 2020-06-17T14:16:56Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T14:17:01Z DEBUG Process finished, return code=0 2020-06-17T14:17:01Z DEBUG stdout= 2020-06-17T14:17:01Z DEBUG stderr= 2020-06-17T14:17:01Z DEBUG Restart of dirsrv@LIN-TEST-LAN.service complete 2020-06-17T14:17:01Z DEBUG Created connection context.ldap2_140529472748344 2020-06-17T14:17:01Z DEBUG step duration: smb __restart_dirsrv 5.36 sec 2020-06-17T14:17:01Z DEBUG [19/24]: adding fallback group 2020-06-17T14:17:01Z DEBUG Fallback group already set, nothing to do 2020-06-17T14:17:01Z DEBUG step duration: smb __add_fallback_group 0.00 sec 2020-06-17T14:17:01Z DEBUG [20/24]: adding Default Trust View 2020-06-17T14:17:01Z DEBUG Default Trust View already exists. 2020-06-17T14:17:01Z DEBUG step duration: smb __add_default_trust_view 0.00 sec 2020-06-17T14:17:01Z DEBUG [21/24]: setting SELinux booleans 2020-06-17T14:17:01Z DEBUG Starting external process 2020-06-17T14:17:01Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T14:17:01Z DEBUG Process finished, return code=0 2020-06-17T14:17:01Z DEBUG stdout= 2020-06-17T14:17:01Z DEBUG stderr= 2020-06-17T14:17:01Z DEBUG Starting external process 2020-06-17T14:17:01Z DEBUG args=['/usr/sbin/getsebool', 'samba_portmapper'] 2020-06-17T14:17:01Z DEBUG Process finished, return code=0 2020-06-17T14:17:01Z DEBUG stdout=samba_portmapper --> on 2020-06-17T14:17:01Z DEBUG stderr= 2020-06-17T14:17:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:17:01Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:17:01Z DEBUG step duration: smb __configure_selinux_for_smbd 0.02 sec 2020-06-17T14:17:01Z DEBUG [22/24]: starting CIFS services 2020-06-17T14:17:01Z DEBUG Starting external process 2020-06-17T14:17:01Z DEBUG args=['/bin/systemctl', 'start', 'smb.service'] 2020-06-17T14:17:01Z DEBUG Process finished, return code=0 2020-06-17T14:17:01Z DEBUG stdout= 2020-06-17T14:17:01Z DEBUG stderr= 2020-06-17T14:17:01Z DEBUG Starting external process 2020-06-17T14:17:01Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T14:17:01Z DEBUG Process finished, return code=0 2020-06-17T14:17:01Z DEBUG stdout=active 2020-06-17T14:17:01Z DEBUG stderr= 2020-06-17T14:17:01Z DEBUG Start of smb.service complete 2020-06-17T14:17:01Z DEBUG Starting external process 2020-06-17T14:17:01Z DEBUG args=['/bin/systemctl', 'start', 'winbind.service'] 2020-06-17T14:17:02Z DEBUG Process finished, return code=0 2020-06-17T14:17:02Z DEBUG stdout= 2020-06-17T14:17:02Z DEBUG stderr= 2020-06-17T14:17:02Z DEBUG Starting external process 2020-06-17T14:17:02Z DEBUG args=['/bin/systemctl', 'is-active', 'winbind.service'] 2020-06-17T14:17:02Z DEBUG Process finished, return code=0 2020-06-17T14:17:02Z DEBUG stdout=active 2020-06-17T14:17:02Z DEBUG stderr= 2020-06-17T14:17:02Z DEBUG Start of winbind.service complete 2020-06-17T14:17:02Z DEBUG step duration: smb __start 0.71 sec 2020-06-17T14:17:02Z DEBUG [23/24]: adding SIDs to existing users and groups 2020-06-17T14:17:02Z DEBUG Starting external process 2020-06-17T14:17:02Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpwhkquj83', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T14:17:02Z DEBUG Process finished, return code=0 2020-06-17T14:17:02Z DEBUG stdout=add objectClass: top extensibleObject add cn: sidgen add nsslapd-basedn: dc=lin,dc=test,dc=lan add delay: 0 adding new entry "cn=sidgen,cn=ipa-sidgen-task,cn=tasks,cn=config" modify complete 2020-06-17T14:17:02Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T14:17:02Z DEBUG This step may take considerable amount of time, please wait.. 2020-06-17T14:17:03Z DEBUG step duration: smb __add_sids 1.02 sec 2020-06-17T14:17:03Z DEBUG [24/24]: restarting smbd 2020-06-17T14:17:03Z DEBUG step duration: smb __restart_smb 0.00 sec 2020-06-17T14:17:03Z DEBUG Done configuring CIFS. 2020-06-17T14:17:03Z DEBUG service duration: smb 7.88 sec 2020-06-17T14:17:03Z DEBUG raw: update_host_cifs_keytabs 2020-06-17T14:17:03Z DEBUG raw: adtrust_is_enabled(version='2.235') 2020-06-17T14:17:03Z DEBUG adtrust_is_enabled(version='2.235') 2020-06-17T14:17:03Z DEBUG Starting external process 2020-06-17T14:17:03Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/krb5.keytab'] 2020-06-17T14:17:03Z DEBUG Process finished, return code=0 2020-06-17T14:17:03Z DEBUG stdout= 2020-06-17T14:17:03Z DEBUG stderr= 2020-06-17T14:17:03Z DEBUG Starting external process 2020-06-17T14:17:03Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/samba/samba.keytab'] 2020-06-17T14:17:03Z DEBUG Process finished, return code=0 2020-06-17T14:17:03Z DEBUG stdout= 2020-06-17T14:17:03Z DEBUG stderr= 2020-06-17T14:17:03Z DEBUG Starting external process 2020-06-17T14:17:03Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T14:17:03Z DEBUG Process finished, return code=0 2020-06-17T14:17:03Z DEBUG stdout= 2020-06-17T14:17:03Z DEBUG stderr= 2020-06-17T14:17:03Z DEBUG Starting external process 2020-06-17T14:17:03Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T14:17:03Z DEBUG Process finished, return code=0 2020-06-17T14:17:03Z DEBUG stdout= 2020-06-17T14:17:03Z DEBUG stderr= 2020-06-17T14:17:03Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', version='2.235') 2020-06-17T14:17:03Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', include_master=False, all=False, raw=False, version='2.235') 2020-06-17T14:17:03Z DEBUG Set service ['ADTRUST'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T14:17:03Z DEBUG Set service ['EXTID'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T14:17:03Z DEBUG raw: dns_is_enabled(version='2.235') 2020-06-17T14:17:03Z DEBUG dns_is_enabled(version='2.235') 2020-06-17T14:17:03Z DEBUG raw: dnszone_show('lin.test.lan', version='2.235') 2020-06-17T14:17:03Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T14:17:03Z DEBUG raw: dns_update_system_records(version='2.235') 2020-06-17T14:17:03Z DEBUG dns_update_system_records(dry_run=False, all=False, raw=False, version='2.235') 2020-06-17T14:17:03Z DEBUG raw: server_find(None, version='2.235', no_members=False, servrole='IPA master') 2020-06-17T14:17:03Z DEBUG server_find(None, all=False, raw=False, version='2.235', no_members=False, pkey_only=False, servrole=('IPA master',)) 2020-06-17T14:17:03Z DEBUG raw: server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, version='2.235') 2020-06-17T14:17:03Z DEBUG server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T14:17:03Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version='2.235') 2020-06-17T14:17:03Z DEBUG topologysuffix_find(None, all=True, raw=True, version='2.235', pkey_only=False) 2020-06-17T14:17:03Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, version='2.235') 2020-06-17T14:17:03Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T14:17:03Z DEBUG raw: dnszone_show(, version='2.235') 2020-06-17T14:17:03Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T14:17:03Z DEBUG found 1 1 records for freeipaserver.lin.test.lan.: 10.0.0.179 2020-06-17T14:17:03Z DEBUG The DNS response does not contain an answer to the question: freeipaserver.lin.test.lan. IN AAAA 2020-06-17T14:17:03Z DEBUG raw: dnsrecord_mod(, , txtrecord=['"LIN.TEST.LAN"'], version='2.235') 2020-06-17T14:17:03Z DEBUG dnsrecord_mod(, , txtrecord=('"LIN.TEST.LAN"',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:17:03Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:17:03Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:17:03Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:17:03Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:17:03Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:17:03Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:17:03Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:17:03Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:17:03Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:17:03Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:17:03Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:17:03Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:17:03Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:17:03Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:17:03Z DEBUG raw: dnsrecord_mod(, , arecord=['10.0.0.179'], version='2.235') 2020-06-17T14:17:03Z DEBUG dnsrecord_mod(, , arecord=('10.0.0.179',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:17:03Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:17:03Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:17:03Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:17:03Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:17:03Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:17:03Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:17:03Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:17:03Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:17:03Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:17:03Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:17:03Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:17:03Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:17:03Z DEBUG raw: location_find(None, version='2.235') 2020-06-17T14:17:03Z DEBUG location_find(None, all=False, raw=False, version='2.235', pkey_only=False) 2020-06-17T14:17:03Z DEBUG Starting external process 2020-06-17T14:17:03Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T14:17:03Z DEBUG Process finished, return code=0 2020-06-17T14:17:03Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T14:17:03Z DEBUG stderr= 2020-06-17T14:17:03Z DEBUG Destroyed connection context.ldap2_140529472748344 2020-06-17T14:17:03Z INFO The ipa-adtrust-install command was successful 2020-06-17T14:27:44Z DEBUG /usr/sbin/ipa-adtrust-install was invoked with options: {'debug': False, 'netbios_name': 'LIN', 'no_msdcs': False, 'rid_base': 1000, 'secondary_rid_base': 100000000, 'unattended': True, 'add_sids': True, 'add_agents': False, 'enable_compat': False} 2020-06-17T14:27:44Z DEBUG missing options might be asked for interactively later 2020-06-17T14:27:44Z DEBUG IPA version 4.8.4-7.module_el8.2.0+374+0d2d74a1 2020-06-17T14:27:44Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T14:27:44Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T14:27:44Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-06-17T14:27:44Z DEBUG importing plugin module ipaserver.plugins.aci 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.automember 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.automount 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-06-17T14:27:45Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.batch 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.ca 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.cert 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.config 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.dns 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.group 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-06-17T14:27:45Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.host 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.idoverride-admemberof 2020-06-17T14:27:45Z DEBUG ipaserver.plugins.idoverride-admemberof is not a valid plugin module 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.internal 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.join 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.location 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.migration 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.misc 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.otp 2020-06-17T14:27:45Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.permission 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.ping 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-06-17T14:27:45Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.role 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.schema 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.server 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.service 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.session 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-06-17T14:27:45Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.topology 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.trust 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.user 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.vault 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-06-17T14:27:45Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-06-17T14:27:45Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-06-17T14:27:46Z DEBUG Starting external process 2020-06-17T14:27:46Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T14:27:46Z DEBUG Process finished, return code=0 2020-06-17T14:27:46Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T14:27:46Z DEBUG stderr= 2020-06-17T14:27:47Z DEBUG Created connection context.ldap2_139814300220216 2020-06-17T14:27:47Z DEBUG raw: user_show('admin', version='2.235') 2020-06-17T14:27:47Z DEBUG user_show('admin', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:27:47Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T14:27:47Z DEBUG raw: group_show('admins', version='2.235') 2020-06-17T14:27:47Z DEBUG group_show('admins', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:27:47Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:27:47Z DEBUG Configuring CIFS 2020-06-17T14:27:47Z DEBUG [1/24]: validate server hostname 2020-06-17T14:27:47Z DEBUG step duration: smb __validate_server_hostname 0.00 sec 2020-06-17T14:27:47Z DEBUG [2/24]: stopping smbd 2020-06-17T14:27:47Z DEBUG Starting external process 2020-06-17T14:27:47Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T14:27:47Z DEBUG Process finished, return code=0 2020-06-17T14:27:47Z DEBUG stdout=active 2020-06-17T14:27:47Z DEBUG stderr= 2020-06-17T14:27:47Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:27:47Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:27:47Z DEBUG Starting external process 2020-06-17T14:27:47Z DEBUG args=['/bin/systemctl', 'stop', 'winbind.service'] 2020-06-17T14:27:47Z DEBUG Process finished, return code=0 2020-06-17T14:27:47Z DEBUG stdout= 2020-06-17T14:27:47Z DEBUG stderr= 2020-06-17T14:27:47Z DEBUG Stop of winbind.service complete 2020-06-17T14:27:47Z DEBUG Starting external process 2020-06-17T14:27:47Z DEBUG args=['/bin/systemctl', 'stop', 'smb.service'] 2020-06-17T14:27:47Z DEBUG Process finished, return code=0 2020-06-17T14:27:47Z DEBUG stdout= 2020-06-17T14:27:47Z DEBUG stderr= 2020-06-17T14:27:47Z DEBUG Stop of smb.service complete 2020-06-17T14:27:47Z DEBUG step duration: smb __stop 0.09 sec 2020-06-17T14:27:47Z DEBUG [3/24]: creating samba domain object 2020-06-17T14:27:47Z DEBUG Samba domain object already exists 2020-06-17T14:27:47Z DEBUG step duration: smb __create_samba_domain_object 0.00 sec 2020-06-17T14:27:47Z DEBUG [4/24]: retrieve local idmap range 2020-06-17T14:27:47Z DEBUG raw: idrange_show('LIN.TEST.LAN_id_range', version='2.235') 2020-06-17T14:27:47Z DEBUG idrange_show('LIN.TEST.LAN_id_range', rights=False, all=False, raw=False, version='2.235') 2020-06-17T14:27:47Z DEBUG step duration: smb __retrieve_local_range 0.00 sec 2020-06-17T14:27:47Z DEBUG [5/24]: creating samba config registry 2020-06-17T14:27:47Z DEBUG Starting external process 2020-06-17T14:27:47Z DEBUG args=['/usr/bin/net', 'conf', 'import', '/tmp/tmpx1nr1m2a'] 2020-06-17T14:27:47Z DEBUG Process finished, return code=0 2020-06-17T14:27:47Z DEBUG stdout= 2020-06-17T14:27:47Z DEBUG stderr= 2020-06-17T14:27:47Z DEBUG step duration: smb __write_smb_registry 0.10 sec 2020-06-17T14:27:47Z DEBUG [6/24]: writing samba config file 2020-06-17T14:27:47Z DEBUG step duration: smb __write_smb_conf 0.00 sec 2020-06-17T14:27:47Z DEBUG [7/24]: adding cifs Kerberos principal 2020-06-17T14:27:47Z DEBUG raw: service_add('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', force=True, version='2.235') 2020-06-17T14:27:47Z DEBUG service_add(ipapython.kerberos.Principal('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN'), force=True, skip_host_check=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:27:47Z DEBUG raw: host_show('freeipaserver.lin.test.lan', version='2.235') 2020-06-17T14:27:47Z DEBUG host_show('freeipaserver.lin.test.lan', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:27:47Z DEBUG Starting external process 2020-06-17T14:27:47Z DEBUG args=['/usr/sbin/ipa-rmkeytab', '--principal', 'cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-k', '/etc/samba/samba.keytab'] 2020-06-17T14:27:47Z DEBUG Process finished, return code=0 2020-06-17T14:27:47Z DEBUG stdout= 2020-06-17T14:27:47Z DEBUG stderr=Suppression du principal cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN 2020-06-17T14:27:47Z DEBUG Removing service credentials cache 2020-06-17T14:27:47Z DEBUG Ccache path: '/var/run/samba/krb5cc_samba' 2020-06-17T14:27:47Z DEBUG Starting external process 2020-06-17T14:27:47Z DEBUG args=['/usr/bin/kdestroy', '-c', '/var/run/samba/krb5cc_samba'] 2020-06-17T14:27:47Z DEBUG Process finished, return code=0 2020-06-17T14:27:47Z DEBUG stdout= 2020-06-17T14:27:47Z DEBUG stderr= 2020-06-17T14:27:47Z DEBUG Starting external process 2020-06-17T14:27:47Z DEBUG args=['/usr/sbin/ipa-getkeytab', '-k', '/etc/samba/samba.keytab', '-p', 'cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T14:27:47Z DEBUG Process finished, return code=0 2020-06-17T14:27:47Z DEBUG stdout= 2020-06-17T14:27:47Z DEBUG stderr=Récupération du tableau de clés et stockage avec succès dans : /etc/samba/samba.keytab 2020-06-17T14:27:47Z DEBUG step duration: smb request_service_keytab 0.07 sec 2020-06-17T14:27:47Z DEBUG [8/24]: adding cifs and host Kerberos principals to the adtrust agents group 2020-06-17T14:27:47Z DEBUG step duration: smb __setup_group_membership 0.00 sec 2020-06-17T14:27:47Z DEBUG [9/24]: check for cifs services defined on other replicas 2020-06-17T14:27:47Z DEBUG step duration: smb __check_replica 0.00 sec 2020-06-17T14:27:47Z DEBUG [10/24]: adding cifs principal to S4U2Proxy targets 2020-06-17T14:27:47Z DEBUG cifs principal already targeted, nothing to do. 2020-06-17T14:27:47Z DEBUG step duration: smb __add_s4u2proxy_target 0.00 sec 2020-06-17T14:27:47Z DEBUG [11/24]: adding admin(group) SIDs 2020-06-17T14:27:47Z DEBUG Admin SID already set, nothing to do 2020-06-17T14:27:47Z DEBUG Admin group SID already set, nothing to do 2020-06-17T14:27:47Z DEBUG step duration: smb __add_admin_sids 0.00 sec 2020-06-17T14:27:47Z DEBUG [12/24]: adding RID bases 2020-06-17T14:27:47Z DEBUG RID bases already set, nothing to do 2020-06-17T14:27:47Z DEBUG step duration: smb __add_rid_bases 0.00 sec 2020-06-17T14:27:47Z DEBUG [13/24]: updating Kerberos config 2020-06-17T14:27:47Z DEBUG 'dns_lookup_kdc' already set to 'true', nothing to do. 2020-06-17T14:27:47Z DEBUG step duration: smb __update_krb5_conf 0.00 sec 2020-06-17T14:27:47Z DEBUG [14/24]: activating CLDAP plugin 2020-06-17T14:27:47Z DEBUG CLDAP plugin already configured, nothing to do 2020-06-17T14:27:47Z DEBUG step duration: smb __add_cldap_module 0.00 sec 2020-06-17T14:27:47Z DEBUG [15/24]: activating sidgen task 2020-06-17T14:27:47Z DEBUG Sidgen task plugin already configured, nothing to do 2020-06-17T14:27:47Z DEBUG step duration: smb __add_sidgen_task 0.00 sec 2020-06-17T14:27:47Z DEBUG [16/24]: map BUILTIN\Guests to nobody group 2020-06-17T14:27:47Z DEBUG Map BUILTIN\Guests to a group 'nobody' 2020-06-17T14:27:47Z DEBUG Starting external process 2020-06-17T14:27:47Z DEBUG args=['/usr/bin/net', '-s', '/dev/null', 'groupmap', 'add', 'sid=S-1-5-32-546', 'unixgroup=nobody', 'type=builtin'] 2020-06-17T14:27:47Z DEBUG Process finished, return code=255 2020-06-17T14:27:47Z DEBUG stdout=Unix group nobody already mapped to SID S-1-5-32-546 2020-06-17T14:27:47Z DEBUG stderr= 2020-06-17T14:27:47Z DEBUG step duration: smb __map_Guests_to_nobody 0.07 sec 2020-06-17T14:27:47Z DEBUG [17/24]: configuring smbd to start on boot 2020-06-17T14:27:47Z DEBUG Starting external process 2020-06-17T14:27:47Z DEBUG args=['/bin/systemctl', 'is-enabled', 'smb.service'] 2020-06-17T14:27:47Z DEBUG Process finished, return code=0 2020-06-17T14:27:47Z DEBUG stdout=enabled 2020-06-17T14:27:47Z DEBUG stderr= 2020-06-17T14:27:47Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:27:47Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:27:47Z DEBUG Starting external process 2020-06-17T14:27:47Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T14:27:47Z DEBUG Process finished, return code=0 2020-06-17T14:27:47Z DEBUG stdout= 2020-06-17T14:27:47Z DEBUG stderr=Removed /etc/systemd/system/multi-user.target.wants/smb.service. 2020-06-17T14:27:47Z DEBUG service ADTRUST has all config values set 2020-06-17T14:27:47Z DEBUG Starting external process 2020-06-17T14:27:47Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T14:27:47Z DEBUG Process finished, return code=0 2020-06-17T14:27:47Z DEBUG stdout= 2020-06-17T14:27:47Z DEBUG stderr= 2020-06-17T14:27:47Z DEBUG service EXTID has all config values set 2020-06-17T14:27:47Z DEBUG step duration: smb __enable 0.39 sec 2020-06-17T14:27:47Z DEBUG [18/24]: restarting Directory Server to take MS PAC and LDAP plugins changes into account 2020-06-17T14:27:47Z DEBUG Destroyed connection context.ldap2_139814300220216 2020-06-17T14:27:47Z DEBUG Starting external process 2020-06-17T14:27:47Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T14:27:51Z DEBUG Process finished, return code=0 2020-06-17T14:27:51Z DEBUG stdout= 2020-06-17T14:27:51Z DEBUG stderr= 2020-06-17T14:27:51Z DEBUG Restart of dirsrv@LIN-TEST-LAN.service complete 2020-06-17T14:27:51Z DEBUG Created connection context.ldap2_139814300220216 2020-06-17T14:27:51Z DEBUG step duration: smb __restart_dirsrv 3.82 sec 2020-06-17T14:27:51Z DEBUG [19/24]: adding fallback group 2020-06-17T14:27:51Z DEBUG Fallback group already set, nothing to do 2020-06-17T14:27:51Z DEBUG step duration: smb __add_fallback_group 0.00 sec 2020-06-17T14:27:51Z DEBUG [20/24]: adding Default Trust View 2020-06-17T14:27:51Z DEBUG Default Trust View already exists. 2020-06-17T14:27:51Z DEBUG step duration: smb __add_default_trust_view 0.00 sec 2020-06-17T14:27:51Z DEBUG [21/24]: setting SELinux booleans 2020-06-17T14:27:51Z DEBUG Starting external process 2020-06-17T14:27:51Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T14:27:51Z DEBUG Process finished, return code=0 2020-06-17T14:27:51Z DEBUG stdout= 2020-06-17T14:27:51Z DEBUG stderr= 2020-06-17T14:27:51Z DEBUG Starting external process 2020-06-17T14:27:51Z DEBUG args=['/usr/sbin/getsebool', 'samba_portmapper'] 2020-06-17T14:27:51Z DEBUG Process finished, return code=0 2020-06-17T14:27:51Z DEBUG stdout=samba_portmapper --> on 2020-06-17T14:27:51Z DEBUG stderr= 2020-06-17T14:27:51Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:27:51Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:27:51Z DEBUG step duration: smb __configure_selinux_for_smbd 0.02 sec 2020-06-17T14:27:51Z DEBUG [22/24]: starting CIFS services 2020-06-17T14:27:51Z DEBUG Starting external process 2020-06-17T14:27:51Z DEBUG args=['/bin/systemctl', 'start', 'smb.service'] 2020-06-17T14:27:52Z DEBUG Process finished, return code=0 2020-06-17T14:27:52Z DEBUG stdout= 2020-06-17T14:27:52Z DEBUG stderr= 2020-06-17T14:27:52Z DEBUG Starting external process 2020-06-17T14:27:52Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T14:27:52Z DEBUG Process finished, return code=0 2020-06-17T14:27:52Z DEBUG stdout=active 2020-06-17T14:27:52Z DEBUG stderr= 2020-06-17T14:27:52Z DEBUG Start of smb.service complete 2020-06-17T14:27:52Z DEBUG Starting external process 2020-06-17T14:27:52Z DEBUG args=['/bin/systemctl', 'start', 'winbind.service'] 2020-06-17T14:27:52Z DEBUG Process finished, return code=0 2020-06-17T14:27:52Z DEBUG stdout= 2020-06-17T14:27:52Z DEBUG stderr= 2020-06-17T14:27:52Z DEBUG Starting external process 2020-06-17T14:27:52Z DEBUG args=['/bin/systemctl', 'is-active', 'winbind.service'] 2020-06-17T14:27:52Z DEBUG Process finished, return code=0 2020-06-17T14:27:52Z DEBUG stdout=active 2020-06-17T14:27:52Z DEBUG stderr= 2020-06-17T14:27:52Z DEBUG Start of winbind.service complete 2020-06-17T14:27:52Z DEBUG step duration: smb __start 0.69 sec 2020-06-17T14:27:52Z DEBUG [23/24]: adding SIDs to existing users and groups 2020-06-17T14:27:52Z DEBUG Starting external process 2020-06-17T14:27:52Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp_3ltjae5', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T14:27:52Z DEBUG Process finished, return code=0 2020-06-17T14:27:52Z DEBUG stdout=add objectClass: top extensibleObject add cn: sidgen add nsslapd-basedn: dc=lin,dc=test,dc=lan add delay: 0 adding new entry "cn=sidgen,cn=ipa-sidgen-task,cn=tasks,cn=config" modify complete 2020-06-17T14:27:52Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T14:27:52Z DEBUG This step may take considerable amount of time, please wait.. 2020-06-17T14:27:53Z DEBUG step duration: smb __add_sids 1.02 sec 2020-06-17T14:27:53Z DEBUG [24/24]: restarting smbd 2020-06-17T14:27:53Z DEBUG step duration: smb __restart_smb 0.00 sec 2020-06-17T14:27:53Z DEBUG Done configuring CIFS. 2020-06-17T14:27:53Z DEBUG service duration: smb 6.30 sec 2020-06-17T14:27:53Z DEBUG raw: update_host_cifs_keytabs 2020-06-17T14:27:53Z DEBUG raw: adtrust_is_enabled(version='2.235') 2020-06-17T14:27:53Z DEBUG adtrust_is_enabled(version='2.235') 2020-06-17T14:27:53Z DEBUG Starting external process 2020-06-17T14:27:53Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/krb5.keytab'] 2020-06-17T14:27:53Z DEBUG Process finished, return code=0 2020-06-17T14:27:53Z DEBUG stdout= 2020-06-17T14:27:53Z DEBUG stderr= 2020-06-17T14:27:53Z DEBUG Starting external process 2020-06-17T14:27:53Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/samba/samba.keytab'] 2020-06-17T14:27:53Z DEBUG Process finished, return code=0 2020-06-17T14:27:53Z DEBUG stdout= 2020-06-17T14:27:53Z DEBUG stderr= 2020-06-17T14:27:53Z DEBUG Starting external process 2020-06-17T14:27:53Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T14:27:53Z DEBUG Process finished, return code=0 2020-06-17T14:27:53Z DEBUG stdout= 2020-06-17T14:27:53Z DEBUG stderr= 2020-06-17T14:27:53Z DEBUG Starting external process 2020-06-17T14:27:53Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T14:27:53Z DEBUG Process finished, return code=0 2020-06-17T14:27:53Z DEBUG stdout= 2020-06-17T14:27:53Z DEBUG stderr= 2020-06-17T14:27:53Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', version='2.235') 2020-06-17T14:27:53Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', include_master=False, all=False, raw=False, version='2.235') 2020-06-17T14:27:53Z DEBUG Set service ['ADTRUST'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T14:27:53Z DEBUG Set service ['EXTID'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T14:27:53Z DEBUG raw: dns_is_enabled(version='2.235') 2020-06-17T14:27:53Z DEBUG dns_is_enabled(version='2.235') 2020-06-17T14:27:53Z DEBUG raw: dnszone_show('lin.test.lan', version='2.235') 2020-06-17T14:27:53Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T14:27:53Z DEBUG raw: dns_update_system_records(version='2.235') 2020-06-17T14:27:53Z DEBUG dns_update_system_records(dry_run=False, all=False, raw=False, version='2.235') 2020-06-17T14:27:53Z DEBUG raw: server_find(None, version='2.235', no_members=False, servrole='IPA master') 2020-06-17T14:27:53Z DEBUG server_find(None, all=False, raw=False, version='2.235', no_members=False, pkey_only=False, servrole=('IPA master',)) 2020-06-17T14:27:53Z DEBUG raw: server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, version='2.235') 2020-06-17T14:27:53Z DEBUG server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T14:27:53Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version='2.235') 2020-06-17T14:27:53Z DEBUG topologysuffix_find(None, all=True, raw=True, version='2.235', pkey_only=False) 2020-06-17T14:27:53Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, version='2.235') 2020-06-17T14:27:53Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T14:27:53Z DEBUG raw: dnszone_show(, version='2.235') 2020-06-17T14:27:53Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T14:27:53Z DEBUG found 1 1 records for freeipaserver.lin.test.lan.: 10.0.0.179 2020-06-17T14:27:53Z DEBUG The DNS response does not contain an answer to the question: freeipaserver.lin.test.lan. IN AAAA 2020-06-17T14:27:53Z DEBUG raw: dnsrecord_mod(, , txtrecord=['"LIN.TEST.LAN"'], version='2.235') 2020-06-17T14:27:53Z DEBUG dnsrecord_mod(, , txtrecord=('"LIN.TEST.LAN"',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:27:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:27:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:27:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:27:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:27:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:27:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:27:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:27:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:27:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:27:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:27:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:27:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:27:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:27:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:27:53Z DEBUG raw: dnsrecord_mod(, , arecord=['10.0.0.179'], version='2.235') 2020-06-17T14:27:53Z DEBUG dnsrecord_mod(, , arecord=('10.0.0.179',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:27:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:27:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:27:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:27:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:27:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:27:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:27:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:27:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:27:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:27:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:27:53Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:27:53Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:27:53Z DEBUG raw: location_find(None, version='2.235') 2020-06-17T14:27:53Z DEBUG location_find(None, all=False, raw=False, version='2.235', pkey_only=False) 2020-06-17T14:27:53Z DEBUG Starting external process 2020-06-17T14:27:53Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T14:27:53Z DEBUG Process finished, return code=0 2020-06-17T14:27:53Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T14:27:53Z DEBUG stderr= 2020-06-17T14:27:53Z DEBUG Destroyed connection context.ldap2_139814300220216 2020-06-17T14:27:53Z INFO The ipa-adtrust-install command was successful 2020-06-17T14:29:20Z DEBUG /usr/sbin/ipa-adtrust-install was invoked with options: {'debug': False, 'netbios_name': 'LIN', 'no_msdcs': False, 'rid_base': 1000, 'secondary_rid_base': 100000000, 'unattended': True, 'add_sids': True, 'add_agents': False, 'enable_compat': False} 2020-06-17T14:29:20Z DEBUG missing options might be asked for interactively later 2020-06-17T14:29:20Z DEBUG IPA version 4.8.4-7.module_el8.2.0+374+0d2d74a1 2020-06-17T14:29:20Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T14:29:20Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-17T14:29:20Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.aci 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.automember 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.automount 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-06-17T14:29:20Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.batch 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.ca 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.cert 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.config 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.dns 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.group 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-06-17T14:29:20Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.host 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.idoverride-admemberof 2020-06-17T14:29:20Z DEBUG ipaserver.plugins.idoverride-admemberof is not a valid plugin module 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.internal 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.join 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.location 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.migration 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.misc 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.otp 2020-06-17T14:29:20Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.permission 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.ping 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-06-17T14:29:20Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.role 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.schema 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-06-17T14:29:20Z DEBUG importing plugin module ipaserver.plugins.server 2020-06-17T14:29:21Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-06-17T14:29:21Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-06-17T14:29:21Z DEBUG importing plugin module ipaserver.plugins.service 2020-06-17T14:29:21Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-06-17T14:29:21Z DEBUG importing plugin module ipaserver.plugins.session 2020-06-17T14:29:21Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-06-17T14:29:21Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-06-17T14:29:21Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-06-17T14:29:21Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-06-17T14:29:21Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-06-17T14:29:21Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-06-17T14:29:21Z DEBUG importing plugin module ipaserver.plugins.topology 2020-06-17T14:29:21Z DEBUG importing plugin module ipaserver.plugins.trust 2020-06-17T14:29:21Z DEBUG importing plugin module ipaserver.plugins.user 2020-06-17T14:29:21Z DEBUG importing plugin module ipaserver.plugins.vault 2020-06-17T14:29:21Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-06-17T14:29:21Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-06-17T14:29:21Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-06-17T14:29:21Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-06-17T14:29:22Z DEBUG Starting external process 2020-06-17T14:29:22Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T14:29:22Z DEBUG Process finished, return code=0 2020-06-17T14:29:22Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T14:29:22Z DEBUG stderr= 2020-06-17T14:29:22Z DEBUG Created connection context.ldap2_140009917229880 2020-06-17T14:29:22Z DEBUG raw: user_show('admin', version='2.235') 2020-06-17T14:29:22Z DEBUG user_show('admin', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:29:22Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket conn= 2020-06-17T14:29:22Z DEBUG raw: group_show('admins', version='2.235') 2020-06-17T14:29:22Z DEBUG group_show('admins', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:29:22Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:29:22Z DEBUG Configuring CIFS 2020-06-17T14:29:22Z DEBUG [1/24]: validate server hostname 2020-06-17T14:29:22Z DEBUG step duration: smb __validate_server_hostname 0.00 sec 2020-06-17T14:29:22Z DEBUG [2/24]: stopping smbd 2020-06-17T14:29:22Z DEBUG Starting external process 2020-06-17T14:29:22Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T14:29:22Z DEBUG Process finished, return code=0 2020-06-17T14:29:22Z DEBUG stdout=active 2020-06-17T14:29:22Z DEBUG stderr= 2020-06-17T14:29:22Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:29:22Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:29:22Z DEBUG Starting external process 2020-06-17T14:29:22Z DEBUG args=['/bin/systemctl', 'stop', 'winbind.service'] 2020-06-17T14:29:22Z DEBUG Process finished, return code=0 2020-06-17T14:29:22Z DEBUG stdout= 2020-06-17T14:29:22Z DEBUG stderr= 2020-06-17T14:29:22Z DEBUG Stop of winbind.service complete 2020-06-17T14:29:22Z DEBUG Starting external process 2020-06-17T14:29:22Z DEBUG args=['/bin/systemctl', 'stop', 'smb.service'] 2020-06-17T14:29:23Z DEBUG Process finished, return code=0 2020-06-17T14:29:23Z DEBUG stdout= 2020-06-17T14:29:23Z DEBUG stderr= 2020-06-17T14:29:23Z DEBUG Stop of smb.service complete 2020-06-17T14:29:23Z DEBUG step duration: smb __stop 0.10 sec 2020-06-17T14:29:23Z DEBUG [3/24]: creating samba domain object 2020-06-17T14:29:23Z DEBUG Samba domain object already exists 2020-06-17T14:29:23Z DEBUG step duration: smb __create_samba_domain_object 0.00 sec 2020-06-17T14:29:23Z DEBUG [4/24]: retrieve local idmap range 2020-06-17T14:29:23Z DEBUG raw: idrange_show('LIN.TEST.LAN_id_range', version='2.235') 2020-06-17T14:29:23Z DEBUG idrange_show('LIN.TEST.LAN_id_range', rights=False, all=False, raw=False, version='2.235') 2020-06-17T14:29:23Z DEBUG step duration: smb __retrieve_local_range 0.00 sec 2020-06-17T14:29:23Z DEBUG [5/24]: creating samba config registry 2020-06-17T14:29:23Z DEBUG Starting external process 2020-06-17T14:29:23Z DEBUG args=['/usr/bin/net', 'conf', 'import', '/tmp/tmpk8i31cm3'] 2020-06-17T14:29:23Z DEBUG Process finished, return code=0 2020-06-17T14:29:23Z DEBUG stdout= 2020-06-17T14:29:23Z DEBUG stderr= 2020-06-17T14:29:23Z DEBUG step duration: smb __write_smb_registry 0.10 sec 2020-06-17T14:29:23Z DEBUG [6/24]: writing samba config file 2020-06-17T14:29:23Z DEBUG step duration: smb __write_smb_conf 0.00 sec 2020-06-17T14:29:23Z DEBUG [7/24]: adding cifs Kerberos principal 2020-06-17T14:29:23Z DEBUG raw: service_add('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', force=True, version='2.235') 2020-06-17T14:29:23Z DEBUG service_add(ipapython.kerberos.Principal('cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN'), force=True, skip_host_check=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:29:23Z DEBUG raw: host_show('freeipaserver.lin.test.lan', version='2.235') 2020-06-17T14:29:23Z DEBUG host_show('freeipaserver.lin.test.lan', rights=False, all=False, raw=False, version='2.235', no_members=False) 2020-06-17T14:29:23Z DEBUG Starting external process 2020-06-17T14:29:23Z DEBUG args=['/usr/sbin/ipa-rmkeytab', '--principal', 'cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-k', '/etc/samba/samba.keytab'] 2020-06-17T14:29:23Z DEBUG Process finished, return code=0 2020-06-17T14:29:23Z DEBUG stdout= 2020-06-17T14:29:23Z DEBUG stderr=Suppression du principal cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN 2020-06-17T14:29:23Z DEBUG Removing service credentials cache 2020-06-17T14:29:23Z DEBUG Ccache path: '/var/run/samba/krb5cc_samba' 2020-06-17T14:29:23Z DEBUG Starting external process 2020-06-17T14:29:23Z DEBUG args=['/usr/bin/kdestroy', '-c', '/var/run/samba/krb5cc_samba'] 2020-06-17T14:29:23Z DEBUG Process finished, return code=0 2020-06-17T14:29:23Z DEBUG stdout= 2020-06-17T14:29:23Z DEBUG stderr= 2020-06-17T14:29:23Z DEBUG Starting external process 2020-06-17T14:29:23Z DEBUG args=['/usr/sbin/ipa-getkeytab', '-k', '/etc/samba/samba.keytab', '-p', 'cifs/freeipaserver.lin.test.lan@LIN.TEST.LAN', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T14:29:23Z DEBUG Process finished, return code=0 2020-06-17T14:29:23Z DEBUG stdout= 2020-06-17T14:29:23Z DEBUG stderr=Récupération du tableau de clés et stockage avec succès dans : /etc/samba/samba.keytab 2020-06-17T14:29:23Z DEBUG step duration: smb request_service_keytab 0.07 sec 2020-06-17T14:29:23Z DEBUG [8/24]: adding cifs and host Kerberos principals to the adtrust agents group 2020-06-17T14:29:23Z DEBUG step duration: smb __setup_group_membership 0.00 sec 2020-06-17T14:29:23Z DEBUG [9/24]: check for cifs services defined on other replicas 2020-06-17T14:29:23Z DEBUG step duration: smb __check_replica 0.00 sec 2020-06-17T14:29:23Z DEBUG [10/24]: adding cifs principal to S4U2Proxy targets 2020-06-17T14:29:23Z DEBUG cifs principal already targeted, nothing to do. 2020-06-17T14:29:23Z DEBUG step duration: smb __add_s4u2proxy_target 0.00 sec 2020-06-17T14:29:23Z DEBUG [11/24]: adding admin(group) SIDs 2020-06-17T14:29:23Z DEBUG Admin SID already set, nothing to do 2020-06-17T14:29:23Z DEBUG Admin group SID already set, nothing to do 2020-06-17T14:29:23Z DEBUG step duration: smb __add_admin_sids 0.00 sec 2020-06-17T14:29:23Z DEBUG [12/24]: adding RID bases 2020-06-17T14:29:23Z DEBUG RID bases already set, nothing to do 2020-06-17T14:29:23Z DEBUG step duration: smb __add_rid_bases 0.00 sec 2020-06-17T14:29:23Z DEBUG [13/24]: updating Kerberos config 2020-06-17T14:29:23Z DEBUG 'dns_lookup_kdc' already set to 'true', nothing to do. 2020-06-17T14:29:23Z DEBUG step duration: smb __update_krb5_conf 0.00 sec 2020-06-17T14:29:23Z DEBUG [14/24]: activating CLDAP plugin 2020-06-17T14:29:23Z DEBUG CLDAP plugin already configured, nothing to do 2020-06-17T14:29:23Z DEBUG step duration: smb __add_cldap_module 0.00 sec 2020-06-17T14:29:23Z DEBUG [15/24]: activating sidgen task 2020-06-17T14:29:23Z DEBUG Sidgen task plugin already configured, nothing to do 2020-06-17T14:29:23Z DEBUG step duration: smb __add_sidgen_task 0.00 sec 2020-06-17T14:29:23Z DEBUG [16/24]: map BUILTIN\Guests to nobody group 2020-06-17T14:29:23Z DEBUG Map BUILTIN\Guests to a group 'nobody' 2020-06-17T14:29:23Z DEBUG Starting external process 2020-06-17T14:29:23Z DEBUG args=['/usr/bin/net', '-s', '/dev/null', 'groupmap', 'add', 'sid=S-1-5-32-546', 'unixgroup=nobody', 'type=builtin'] 2020-06-17T14:29:23Z DEBUG Process finished, return code=255 2020-06-17T14:29:23Z DEBUG stdout=Unix group nobody already mapped to SID S-1-5-32-546 2020-06-17T14:29:23Z DEBUG stderr= 2020-06-17T14:29:23Z DEBUG step duration: smb __map_Guests_to_nobody 0.07 sec 2020-06-17T14:29:23Z DEBUG [17/24]: configuring smbd to start on boot 2020-06-17T14:29:23Z DEBUG Starting external process 2020-06-17T14:29:23Z DEBUG args=['/bin/systemctl', 'is-enabled', 'smb.service'] 2020-06-17T14:29:23Z DEBUG Process finished, return code=0 2020-06-17T14:29:23Z DEBUG stdout=enabled 2020-06-17T14:29:23Z DEBUG stderr= 2020-06-17T14:29:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:29:23Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:29:23Z DEBUG Starting external process 2020-06-17T14:29:23Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T14:29:23Z DEBUG Process finished, return code=0 2020-06-17T14:29:23Z DEBUG stdout= 2020-06-17T14:29:23Z DEBUG stderr=Removed /etc/systemd/system/multi-user.target.wants/smb.service. 2020-06-17T14:29:23Z DEBUG service ADTRUST has all config values set 2020-06-17T14:29:23Z DEBUG Starting external process 2020-06-17T14:29:23Z DEBUG args=['/bin/systemctl', 'disable', 'smb.service'] 2020-06-17T14:29:23Z DEBUG Process finished, return code=0 2020-06-17T14:29:23Z DEBUG stdout= 2020-06-17T14:29:23Z DEBUG stderr= 2020-06-17T14:29:23Z DEBUG service EXTID has all config values set 2020-06-17T14:29:23Z DEBUG step duration: smb __enable 0.39 sec 2020-06-17T14:29:23Z DEBUG [18/24]: restarting Directory Server to take MS PAC and LDAP plugins changes into account 2020-06-17T14:29:23Z DEBUG Destroyed connection context.ldap2_140009917229880 2020-06-17T14:29:23Z DEBUG Starting external process 2020-06-17T14:29:23Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@LIN-TEST-LAN.service'] 2020-06-17T14:29:29Z DEBUG Process finished, return code=0 2020-06-17T14:29:29Z DEBUG stdout= 2020-06-17T14:29:29Z DEBUG stderr= 2020-06-17T14:29:29Z DEBUG Restart of dirsrv@LIN-TEST-LAN.service complete 2020-06-17T14:29:29Z DEBUG Created connection context.ldap2_140009917229880 2020-06-17T14:29:29Z DEBUG step duration: smb __restart_dirsrv 5.35 sec 2020-06-17T14:29:29Z DEBUG [19/24]: adding fallback group 2020-06-17T14:29:29Z DEBUG Fallback group already set, nothing to do 2020-06-17T14:29:29Z DEBUG step duration: smb __add_fallback_group 0.00 sec 2020-06-17T14:29:29Z DEBUG [20/24]: adding Default Trust View 2020-06-17T14:29:29Z DEBUG Default Trust View already exists. 2020-06-17T14:29:29Z DEBUG step duration: smb __add_default_trust_view 0.00 sec 2020-06-17T14:29:29Z DEBUG [21/24]: setting SELinux booleans 2020-06-17T14:29:29Z DEBUG Starting external process 2020-06-17T14:29:29Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-17T14:29:29Z DEBUG Process finished, return code=0 2020-06-17T14:29:29Z DEBUG stdout= 2020-06-17T14:29:29Z DEBUG stderr= 2020-06-17T14:29:29Z DEBUG Starting external process 2020-06-17T14:29:29Z DEBUG args=['/usr/sbin/getsebool', 'samba_portmapper'] 2020-06-17T14:29:29Z DEBUG Process finished, return code=0 2020-06-17T14:29:29Z DEBUG stdout=samba_portmapper --> on 2020-06-17T14:29:29Z DEBUG stderr= 2020-06-17T14:29:29Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:29:29Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-17T14:29:29Z DEBUG step duration: smb __configure_selinux_for_smbd 0.02 sec 2020-06-17T14:29:29Z DEBUG [22/24]: starting CIFS services 2020-06-17T14:29:29Z DEBUG Starting external process 2020-06-17T14:29:29Z DEBUG args=['/bin/systemctl', 'start', 'smb.service'] 2020-06-17T14:29:29Z DEBUG Process finished, return code=0 2020-06-17T14:29:29Z DEBUG stdout= 2020-06-17T14:29:29Z DEBUG stderr= 2020-06-17T14:29:29Z DEBUG Starting external process 2020-06-17T14:29:29Z DEBUG args=['/bin/systemctl', 'is-active', 'smb.service'] 2020-06-17T14:29:29Z DEBUG Process finished, return code=0 2020-06-17T14:29:29Z DEBUG stdout=active 2020-06-17T14:29:29Z DEBUG stderr= 2020-06-17T14:29:29Z DEBUG Start of smb.service complete 2020-06-17T14:29:29Z DEBUG Starting external process 2020-06-17T14:29:29Z DEBUG args=['/bin/systemctl', 'start', 'winbind.service'] 2020-06-17T14:29:29Z DEBUG Process finished, return code=0 2020-06-17T14:29:29Z DEBUG stdout= 2020-06-17T14:29:29Z DEBUG stderr= 2020-06-17T14:29:29Z DEBUG Starting external process 2020-06-17T14:29:29Z DEBUG args=['/bin/systemctl', 'is-active', 'winbind.service'] 2020-06-17T14:29:29Z DEBUG Process finished, return code=0 2020-06-17T14:29:29Z DEBUG stdout=active 2020-06-17T14:29:29Z DEBUG stderr= 2020-06-17T14:29:29Z DEBUG Start of winbind.service complete 2020-06-17T14:29:29Z DEBUG step duration: smb __start 0.63 sec 2020-06-17T14:29:29Z DEBUG [23/24]: adding SIDs to existing users and groups 2020-06-17T14:29:29Z DEBUG Starting external process 2020-06-17T14:29:29Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp9dv0xemf', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket', '-Y', 'EXTERNAL'] 2020-06-17T14:29:29Z DEBUG Process finished, return code=0 2020-06-17T14:29:29Z DEBUG stdout=add objectClass: top extensibleObject add cn: sidgen add nsslapd-basedn: dc=lin,dc=test,dc=lan add delay: 0 adding new entry "cn=sidgen,cn=ipa-sidgen-task,cn=tasks,cn=config" modify complete 2020-06-17T14:29:29Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-LIN-TEST-LAN.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-17T14:29:29Z DEBUG This step may take considerable amount of time, please wait.. 2020-06-17T14:29:30Z DEBUG step duration: smb __add_sids 1.03 sec 2020-06-17T14:29:30Z DEBUG [24/24]: restarting smbd 2020-06-17T14:29:30Z DEBUG step duration: smb __restart_smb 0.00 sec 2020-06-17T14:29:30Z DEBUG Done configuring CIFS. 2020-06-17T14:29:30Z DEBUG service duration: smb 7.77 sec 2020-06-17T14:29:30Z DEBUG raw: update_host_cifs_keytabs 2020-06-17T14:29:30Z DEBUG raw: adtrust_is_enabled(version='2.235') 2020-06-17T14:29:30Z DEBUG adtrust_is_enabled(version='2.235') 2020-06-17T14:29:30Z DEBUG Starting external process 2020-06-17T14:29:30Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/krb5.keytab'] 2020-06-17T14:29:30Z DEBUG Process finished, return code=0 2020-06-17T14:29:30Z DEBUG stdout= 2020-06-17T14:29:30Z DEBUG stderr= 2020-06-17T14:29:30Z DEBUG Starting external process 2020-06-17T14:29:30Z DEBUG args=['/usr/bin/klist', '-eK', '-k', '/etc/samba/samba.keytab'] 2020-06-17T14:29:30Z DEBUG Process finished, return code=0 2020-06-17T14:29:30Z DEBUG stdout= 2020-06-17T14:29:30Z DEBUG stderr= 2020-06-17T14:29:30Z DEBUG Starting external process 2020-06-17T14:29:30Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T14:29:30Z DEBUG Process finished, return code=0 2020-06-17T14:29:30Z DEBUG stdout= 2020-06-17T14:29:30Z DEBUG stderr= 2020-06-17T14:29:30Z DEBUG Starting external process 2020-06-17T14:29:30Z DEBUG args=['/usr/bin/ktutil'] 2020-06-17T14:29:30Z DEBUG Process finished, return code=0 2020-06-17T14:29:30Z DEBUG stdout= 2020-06-17T14:29:30Z DEBUG stderr= 2020-06-17T14:29:30Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', version='2.235') 2020-06-17T14:29:30Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', role_servrole='IPA master', status='hidden', include_master=False, all=False, raw=False, version='2.235') 2020-06-17T14:29:30Z DEBUG Set service ['ADTRUST'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T14:29:30Z DEBUG Set service ['EXTID'] for freeipaserver.lin.test.lan to enabledService 2020-06-17T14:29:30Z DEBUG raw: dns_is_enabled(version='2.235') 2020-06-17T14:29:30Z DEBUG dns_is_enabled(version='2.235') 2020-06-17T14:29:30Z DEBUG raw: dnszone_show('lin.test.lan', version='2.235') 2020-06-17T14:29:30Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T14:29:30Z DEBUG raw: dns_update_system_records(version='2.235') 2020-06-17T14:29:30Z DEBUG dns_update_system_records(dry_run=False, all=False, raw=False, version='2.235') 2020-06-17T14:29:30Z DEBUG raw: server_find(None, version='2.235', no_members=False, servrole='IPA master') 2020-06-17T14:29:30Z DEBUG server_find(None, all=False, raw=False, version='2.235', no_members=False, pkey_only=False, servrole=('IPA master',)) 2020-06-17T14:29:30Z DEBUG raw: server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, version='2.235') 2020-06-17T14:29:30Z DEBUG server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T14:29:30Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version='2.235') 2020-06-17T14:29:30Z DEBUG topologysuffix_find(None, all=True, raw=True, version='2.235', pkey_only=False) 2020-06-17T14:29:30Z DEBUG raw: server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, version='2.235') 2020-06-17T14:29:30Z DEBUG server_role_find(None, server_server='freeipaserver.lin.test.lan', status='enabled', include_master=True, all=False, raw=False, version='2.235') 2020-06-17T14:29:30Z DEBUG raw: dnszone_show(, version='2.235') 2020-06-17T14:29:30Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.235') 2020-06-17T14:29:30Z DEBUG found 1 1 records for freeipaserver.lin.test.lan.: 10.0.0.179 2020-06-17T14:29:30Z DEBUG The DNS response does not contain an answer to the question: freeipaserver.lin.test.lan. IN AAAA 2020-06-17T14:29:30Z DEBUG raw: dnsrecord_mod(, , txtrecord=['"LIN.TEST.LAN"'], version='2.235') 2020-06-17T14:29:30Z DEBUG dnsrecord_mod(, , txtrecord=('"LIN.TEST.LAN"',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:29:30Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:29:30Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:29:30Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:29:30Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:29:30Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:29:30Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:29:30Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:29:30Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:29:30Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:29:30Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:29:30Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:29:30Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:29:30Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:29:30Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:29:30Z DEBUG raw: dnsrecord_mod(, , arecord=['10.0.0.179'], version='2.235') 2020-06-17T14:29:30Z DEBUG dnsrecord_mod(, , arecord=('10.0.0.179',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:29:30Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:29:30Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:29:30Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:29:30Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:29:30Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:29:30Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:29:30Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:29:30Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:29:30Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:29:30Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:29:30Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 freeipaserver.lin.test.lan.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.235') 2020-06-17T14:29:30Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 freeipaserver.lin.test.lan.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.235') 2020-06-17T14:29:30Z DEBUG raw: location_find(None, version='2.235') 2020-06-17T14:29:30Z DEBUG location_find(None, all=False, raw=False, version='2.235', pkey_only=False) 2020-06-17T14:29:30Z DEBUG Starting external process 2020-06-17T14:29:30Z DEBUG args=['/usr/bin/kinit', 'admin'] 2020-06-17T14:29:31Z DEBUG Process finished, return code=0 2020-06-17T14:29:31Z DEBUG stdout=Password for admin@LIN.TEST.LAN: 2020-06-17T14:29:31Z DEBUG stderr= 2020-06-17T14:29:31Z DEBUG Destroyed connection context.ldap2_140009917229880 2020-06-17T14:29:31Z INFO The ipa-adtrust-install command was successful