[root@ipat2 ~]# ipa-server-install --ip-address 10.254.4.94 The log file for this installation can be found in /var/log/ipaserver-install.log ============================================================================== This program will set up the IPA Server. This includes: * Configure a stand-alone CA (dogtag) for certificate management * Configure the Network Time Daemon (ntpd) * Create and configure an instance of Directory Server * Create and configure a Kerberos Key Distribution Center (KDC) * Configure Apache (httpd) * Configure the KDC to enable PKINIT To accept the default shown in brackets, press the Enter key. Do you want to configure integrated DNS (BIND)? [no]: Enter the fully qualified domain name of the computer on which you're setting up server software. Using the form . Example: master.example.com. Server host name [ipat2.ipa.corp.int]: The domain name has been determined based on the host name. Please confirm the domain name [ipa.corp.int]: The kerberos protocol requires a Realm name to be defined. This is typically the domain name converted to uppercase. Please provide a realm name [IPA.CORP.INT]: Certain directory server operations require an administrative user. This user is referred to as the Directory Manager and has full access to the Directory for system management tasks and will be added to the instance of directory server created for IPA. The password must be at least 8 characters long. Directory Manager password: Password (confirm): The IPA server requires an administrative user, named 'admin'. This user is a regular system account used for IPA server administration. IPA admin password: Password (confirm): The IPA Master Server will be configured with: Hostname: ipat2.ipa.corp.int IP address(es): 10.254.4.94 Domain name: ipa.corp.int Realm name: IPA.CORP.INT Continue to configure the system with these values? [no]: yes The following operations may take some minutes to complete. Please wait until the prompt is returned. Configuring NTP daemon (ntpd) [1/4]: stopping ntpd [2/4]: writing configuration [3/4]: configuring ntpd to start on boot [4/4]: starting ntpd Done configuring NTP daemon (ntpd). Configuring directory server (dirsrv). Estimated time: 30 seconds [1/45]: creating directory server instance [2/45]: enabling ldapi [3/45]: configure autobind for root [4/45]: stopping directory server [5/45]: updating configuration in dse.ldif [6/45]: starting directory server [7/45]: adding default schema [8/45]: enabling memberof plugin [9/45]: enabling winsync plugin [10/45]: configuring replication version plugin [11/45]: enabling IPA enrollment plugin [12/45]: configuring uniqueness plugin [13/45]: configuring uuid plugin [14/45]: configuring modrdn plugin [15/45]: configuring DNS plugin [16/45]: enabling entryUSN plugin [17/45]: configuring lockout plugin [18/45]: configuring topology plugin [19/45]: creating indices [20/45]: enabling referential integrity plugin [21/45]: configuring certmap.conf [22/45]: configure new location for managed entries [23/45]: configure dirsrv ccache [24/45]: enabling SASL mapping fallback [25/45]: restarting directory server [26/45]: adding sasl mappings to the directory [27/45]: adding default layout [28/45]: adding delegation layout [29/45]: creating container for managed entries [30/45]: configuring user private groups [31/45]: configuring netgroups from hostgroups [32/45]: creating default Sudo bind user [33/45]: creating default Auto Member layout [34/45]: adding range check plugin [35/45]: creating default HBAC rule allow_all [36/45]: adding entries for topology management [37/45]: initializing group membership [38/45]: adding master entry [39/45]: initializing domain level [40/45]: configuring Posix uid/gid generation [41/45]: adding replication acis [42/45]: activating sidgen plugin [43/45]: activating extdom plugin [44/45]: tuning directory server [45/45]: configuring directory to start on boot Done configuring directory server (dirsrv). Configuring Kerberos KDC (krb5kdc) [1/10]: adding kerberos container to the directory [2/10]: configuring KDC [3/10]: initialize kerberos container [4/10]: adding default ACIs [5/10]: creating a keytab for the directory [6/10]: creating a keytab for the machine [7/10]: adding the password extension to the directory [8/10]: creating anonymous principal [9/10]: starting the KDC [10/10]: configuring KDC to start on boot Done configuring Kerberos KDC (krb5kdc). Configuring kadmin [1/2]: starting kadmin [2/2]: configuring kadmin to start on boot Done configuring kadmin. Configuring certificate server (pki-tomcatd). Estimated time: 3 minutes [1/29]: configuring certificate server instance [2/29]: exporting Dogtag certificate store pin [3/29]: stopping certificate server instance to update CS.cfg [4/29]: backing up CS.cfg [5/29]: disabling nonces [6/29]: set up CRL publishing [7/29]: enable PKIX certificate path discovery and validation [8/29]: starting certificate server instance [9/29]: configure certmonger for renewals [10/29]: requesting RA certificate from CA [11/29]: setting up signing cert profile [12/29]: setting audit signing renewal to 2 years [13/29]: restarting certificate server [14/29]: publishing the CA certificate [15/29]: adding RA agent as a trusted user [16/29]: authorizing RA to modify profiles [17/29]: authorizing RA to manage lightweight CAs [18/29]: Ensure lightweight CAs container exists [19/29]: configure certificate renewals [20/29]: configure Server-Cert certificate renewal [21/29]: Configure HTTP to proxy connections [22/29]: restarting certificate server [23/29]: updating IPA configuration [24/29]: enabling CA instance [25/29]: migrating certificate profiles to LDAP [26/29]: importing IPA certificate profiles [27/29]: adding default CA ACL [28/29]: adding 'ipa' CA entry [29/29]: configuring certmonger renewal for lightweight CAs Done configuring certificate server (pki-tomcatd). Configuring directory server (dirsrv) [1/3]: configuring TLS for DS instance [2/3]: adding CA certificate entry [3/3]: restarting directory server Done configuring directory server (dirsrv). Configuring ipa-otpd [1/2]: starting ipa-otpd [2/2]: configuring ipa-otpd to start on boot Done configuring ipa-otpd. Configuring ipa-custodia [1/5]: Generating ipa-custodia config file [2/5]: Making sure custodia container exists [3/5]: Generating ipa-custodia keys [4/5]: starting ipa-custodia [5/5]: configuring ipa-custodia to start on boot Done configuring ipa-custodia. Configuring the web interface (httpd) [1/22]: stopping httpd [2/22]: setting mod_nss port to 443 [3/22]: setting mod_nss cipher suite [4/22]: setting mod_nss protocol list to TLSv1.0 - TLSv1.2 [5/22]: setting mod_nss password file [6/22]: enabling mod_nss renegotiate [7/22]: disabling mod_nss OCSP [8/22]: adding URL rewriting rules [9/22]: configuring httpd [10/22]: setting up httpd keytab [11/22]: configuring Gssproxy [12/22]: setting up ssl [13/22]: configure certmonger for renewals [14/22]: importing CA certificates from LDAP [15/22]: publish CA cert [16/22]: clean up any existing httpd ccaches [17/22]: configuring SELinux for httpd [18/22]: create KDC proxy config [19/22]: enable KDC proxy [20/22]: starting httpd [21/22]: configuring httpd to start on boot [22/22]: enabling oddjobd Done configuring the web interface (httpd). Configuring Kerberos KDC (krb5kdc) [1/1]: installing X509 Certificate for PKINIT Done configuring Kerberos KDC (krb5kdc). Applying LDAP updates Upgrading IPA:. Estimated time: 1 minute 30 seconds [1/9]: stopping directory server [2/9]: saving configuration [3/9]: disabling listeners [4/9]: enabling DS global lock [5/9]: starting directory server [6/9]: upgrading server [7/9]: stopping directory server [8/9]: restoring configuration [9/9]: starting directory server Done. Restarting the KDC ipa : ERROR unable to resolve host name ipat2.ipa.corp.int. to IP address, ipa-ca DNS record will be incomplete Please add records in this file to your DNS system: /tmp/ipa.system.records.p_Rpfi.db Configuring client side components Using existing certificate '/etc/ipa/ca.crt'. Client hostname: ipat2.ipa.corp.int Realm: IPA.CORP.INT DNS Domain: ipa.corp.int IPA Server: ipat2.ipa.corp.int BaseDN: dc=ipa,dc=corp,dc=int Skipping synchronizing time with NTP server. New SSSD config will be created Configured sudoers in /etc/nsswitch.conf Configured /etc/sssd/sssd.conf trying https://ipat2.ipa.corp.int/ipa/json [try 1]: Forwarding 'schema' to json server 'https://ipat2.ipa.corp.int/ipa/json' trying https://ipat2.ipa.corp.int/ipa/session/json [try 1]: Forwarding 'ping' to json server 'https://ipat2.ipa.corp.int/ipa/session/json' [try 1]: Forwarding 'ca_is_enabled' to json server 'https://ipat2.ipa.corp.int/ipa/session/json' Systemwide CA database updated. Adding SSH public key from /etc/ssh/ssh_host_rsa_key.pub Adding SSH public key from /etc/ssh/ssh_host_ecdsa_key.pub Adding SSH public key from /etc/ssh/ssh_host_ed25519_key.pub [try 1]: Forwarding 'host_mod' to json server 'https://ipat2.ipa.corp.int/ipa/session/json' Could not update DNS SSHFP records. SSSD enabled Configured /etc/openldap/ldap.conf Configured /etc/ssh/ssh_config Configured /etc/ssh/sshd_config Configuring ipa.corp.int as NIS domain. Client configuration complete. The ipa-client-install command was successful ============================================================================== Setup complete Next steps: 1. You must make sure these network ports are open: TCP Ports: * 80, 443: HTTP/HTTPS * 389, 636: LDAP/LDAPS * 88, 464: kerberos UDP Ports: * 88, 464: kerberos * 123: ntp 2. You can now obtain a kerberos ticket using the command: 'kinit admin' This ticket will allow you to use the IPA tools (e.g., ipa user-add) and the web user interface. Be sure to back up the CA certificates stored in /root/cacert.p12 These files are required to create replicas. The password for these files is the Directory Manager password [root@ipat2 ~]# netstat -tlpn Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name tcp 0 0 0.0.0.0:749 0.0.0.0:* LISTEN 15288/kadmind tcp 0 0 0.0.0.0:111 0.0.0.0:* LISTEN 1/systemd tcp 0 0 0.0.0.0:464 0.0.0.0:* LISTEN 15288/kadmind tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 18380/sshd tcp 0 0 0.0.0.0:88 0.0.0.0:* LISTEN 18266/krb5kdc tcp 0 0 127.0.0.1:25 0.0.0.0:* LISTEN 1548/master tcp6 0 0 :::749 :::* LISTEN 15288/kadmind tcp6 0 0 :::111 :::* LISTEN 1/systemd tcp6 0 0 :::80 :::* LISTEN 17835/httpd tcp6 0 0 :::8080 :::* LISTEN 17475/java tcp6 0 0 :::464 :::* LISTEN 15288/kadmind tcp6 0 0 :::22 :::* LISTEN 18380/sshd tcp6 0 0 :::88 :::* LISTEN 18266/krb5kdc tcp6 0 0 ::1:25 :::* LISTEN 1548/master tcp6 0 0 :::443 :::* LISTEN 17835/httpd tcp6 0 0 :::8443 :::* LISTEN 17475/java tcp6 0 0 :::636 :::* LISTEN 18208/ns-slapd tcp6 0 0 :::389 :::* LISTEN 18208/ns-slapd tcp6 0 0 127.0.0.1:8005 :::* LISTEN 17475/java tcp6 0 0 127.0.0.1:8009 :::* LISTEN 17475/java [root@ipat2 ~]# head -n 200 /var/log/ipaserver-install.log 2018-02-20T12:55:51Z DEBUG Logging to /var/log/ipaserver-install.log 2018-02-20T12:55:51Z DEBUG ipa-server-install was invoked with arguments [] and options: {'no_dns_sshfp': False, 'ignore_topology_disconnect': False, 'verbose': False, 'domain_level': None, 'ip_addresses': [CheckedIPAddress('10.254.4.94')], 'secondary_rid_base': None, 'netbios_name': None, 'mkhomedir': False, 'http_cert_files': None, 'zonemgr': None, 'no_pkinit': False, 'reverse_zones': None, 'no_forwarders': False, 'external_ca_type': None, 'no_ntp': False, 'no_msdcs': False, 'setup_kra': False, 'domain_name': None, 'idmax': None, 'setup_adtrust': False, 'http_cert_name': None, 'dirsrv_cert_files': None, 'no_dnssec_validation': False, 'ca_signing_algorithm': None, 'no_reverse': False, 'ssh_trust_dns': False, 'pkinit_cert_files': None, 'ca_cert_files': None, 'subject_base': None, 'auto_reverse': False, 'auto_forwarders': False, 'no_host_dns': False, 'no_sshd': False, 'no_ui_redirect': False, 'ignore_last_of_role': False, 'realm_name': None, 'forwarders': None, 'idstart': None, 'external_ca': False, 'pkinit_cert_name': None, 'no_ssh': False, 'external_cert_files': None, 'enable_compat': False, 'no_hbac_allow': False, 'forward_policy': None, 'dirsrv_cert_name': None, 'unattended': False, 'rid_base': None, 'quiet': False, 'setup_dns': False, 'ca_subject': None, 'host_name': None, 'dirsrv_config_file': None, 'log_file': None, 'allow_zone_overlap': False, 'uninstall': False} 2018-02-20T12:55:51Z DEBUG IPA version 4.5.0-22.el7.centos 2018-02-20T12:55:51Z DEBUG Starting external process 2018-02-20T12:55:51Z DEBUG args=/usr/sbin/selinuxenabled 2018-02-20T12:55:51Z DEBUG Process finished, return code=0 2018-02-20T12:55:51Z DEBUG stdout= 2018-02-20T12:55:51Z DEBUG stderr= 2018-02-20T12:55:51Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-20T12:55:51Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-20T12:55:51Z DEBUG httpd is not configured 2018-02-20T12:55:51Z DEBUG kadmin is not configured 2018-02-20T12:55:51Z DEBUG dirsrv is not configured 2018-02-20T12:55:51Z DEBUG pki-tomcatd is not configured 2018-02-20T12:55:51Z DEBUG install is not configured 2018-02-20T12:55:51Z DEBUG krb5kdc is not configured 2018-02-20T12:55:51Z DEBUG ntpd is not configured 2018-02-20T12:55:51Z DEBUG named is not configured 2018-02-20T12:55:51Z DEBUG filestore is tracking no files 2018-02-20T12:55:51Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2018-02-20T12:55:51Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-20T12:55:51Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-20T12:55:51Z DEBUG Starting external process 2018-02-20T12:55:51Z DEBUG args=/bin/systemctl is-enabled chronyd.service 2018-02-20T12:55:51Z DEBUG Process finished, return code=1 2018-02-20T12:55:51Z DEBUG stdout= 2018-02-20T12:55:51Z DEBUG stderr=Failed to get unit file state for chronyd.service: No such file or directory 2018-02-20T12:55:51Z DEBUG Starting external process 2018-02-20T12:55:51Z DEBUG args=/bin/systemctl is-active chronyd.service 2018-02-20T12:55:51Z DEBUG Process finished, return code=3 2018-02-20T12:55:51Z DEBUG stdout=unknown 2018-02-20T12:55:51Z DEBUG stderr= 2018-02-20T12:55:51Z DEBUG Starting external process 2018-02-20T12:55:51Z DEBUG args=/usr/sbin/httpd -t -D DUMP_VHOSTS 2018-02-20T12:55:51Z DEBUG Process finished, return code=0 2018-02-20T12:55:51Z DEBUG stdout=VirtualHost configuration: *:8443 ipat2.ipa.corp.int (/etc/httpd/conf.d/nss.conf:83) 2018-02-20T12:55:51Z DEBUG stderr= 2018-02-20T12:55:57Z DEBUG Check if ipat2.ipa.corp.int is a primary hostname for localhost 2018-02-20T12:55:57Z DEBUG Primary hostname for localhost: ipat2.ipa.corp.int 2018-02-20T12:55:57Z DEBUG Search DNS for ipat2.ipa.corp.int 2018-02-20T12:55:57Z DEBUG Check if ipat2.ipa.corp.int is not a CNAME 2018-02-20T12:55:57Z DEBUG Check reverse address of 10.254.4.94 2018-02-20T12:55:57Z DEBUG Found reverse name: ipat2.ipa.corp.int 2018-02-20T12:55:57Z DEBUG will use host_name: ipat2.ipa.corp.int 2018-02-20T12:56:03Z DEBUG read domain_name: ipa.corp.int 2018-02-20T12:56:05Z DEBUG read realm_name: IPA.CORP.INT 2018-02-20T12:56:16Z DEBUG importing all plugin modules in ipaserver.plugins... 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.aci 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.automember 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.automount 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.baseldap 2018-02-20T12:56:16Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.baseuser 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.batch 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.ca 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.caacl 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.cert 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.certmap 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.certprofile 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.config 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.delegation 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.dns 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.dogtag 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.group 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.hbac 2018-02-20T12:56:16Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.hbactest 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.host 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.idrange 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.idviews 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.internal 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.join 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.ldap2 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.location 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.migration 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.misc 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.netgroup 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.otp 2018-02-20T12:56:16Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.otptoken 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.passwd 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.permission 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.ping 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.pkinit 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.privilege 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.rabase 2018-02-20T12:56:16Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.role 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.schema 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.selfservice 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.server 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.serverrole 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.serverroles 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.service 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.session 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.stageuser 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.sudo 2018-02-20T12:56:16Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.sudorule 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.topology 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.trust 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.user 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.vault 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.virtual 2018-02-20T12:56:16Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.whoami 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2018-02-20T12:56:16Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.install.plugins.dns 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2018-02-20T12:56:16Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2018-02-20T12:56:18Z DEBUG Name ipat2.ipa.corp.int resolved to set([UnsafeIPAddress('10.254.4.94')]) 2018-02-20T12:56:21Z DEBUG Backing up system configuration file '/etc/hosts' 2018-02-20T12:56:21Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-20T12:56:21Z DEBUG Starting external process 2018-02-20T12:56:21Z DEBUG args=/bin/systemctl is-enabled chronyd.service 2018-02-20T12:56:21Z DEBUG Process finished, return code=1 2018-02-20T12:56:21Z DEBUG stdout= 2018-02-20T12:56:21Z DEBUG stderr=Failed to get unit file state for chronyd.service: No such file or directory 2018-02-20T12:56:21Z DEBUG Starting external process 2018-02-20T12:56:21Z DEBUG args=/bin/systemctl is-active chronyd.service 2018-02-20T12:56:21Z DEBUG Process finished, return code=3 2018-02-20T12:56:21Z DEBUG stdout=unknown 2018-02-20T12:56:21Z DEBUG stderr= 2018-02-20T12:56:21Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-20T12:56:21Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-20T12:56:21Z DEBUG Configuring NTP daemon (ntpd) 2018-02-20T12:56:21Z DEBUG [1/4]: stopping ntpd 2018-02-20T12:56:21Z DEBUG Starting external process 2018-02-20T12:56:21Z DEBUG args=/bin/systemctl is-active ntpd.service 2018-02-20T12:56:21Z DEBUG Process finished, return code=3 2018-02-20T12:56:21Z DEBUG stdout=unknown 2018-02-20T12:56:21Z DEBUG stderr= 2018-02-20T12:56:21Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-20T12:56:21Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-20T12:56:21Z DEBUG Starting external process 2018-02-20T12:56:21Z DEBUG args=/bin/systemctl stop ntpd.service 2018-02-20T12:56:21Z DEBUG Process finished, return code=0 2018-02-20T12:56:21Z DEBUG stdout= 2018-02-20T12:56:21Z DEBUG stderr= 2018-02-20T12:56:21Z DEBUG duration: 0 seconds 2018-02-20T12:56:21Z DEBUG [2/4]: writing configuration 2018-02-20T12:56:21Z DEBUG Backing up system configuration file '/etc/ntp.conf' 2018-02-20T12:56:21Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-20T12:56:21Z DEBUG Backing up system configuration file '/etc/sysconfig/ntpd' 2018-02-20T12:56:21Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-20T12:56:21Z DEBUG duration: 0 seconds 2018-02-20T12:56:21Z DEBUG [3/4]: configuring ntpd to start on boot 2018-02-20T12:56:21Z DEBUG Starting external process 2018-02-20T12:56:21Z DEBUG args=/bin/systemctl is-enabled ntpd.service 2018-02-20T12:56:21Z DEBUG Process finished, return code=1 2018-02-20T12:56:21Z DEBUG stdout=disabled 2018-02-20T12:56:21Z DEBUG stderr= 2018-02-20T12:56:21Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-20T12:56:21Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-20T12:56:21Z DEBUG Starting external process 2018-02-20T12:56:21Z DEBUG args=/bin/systemctl enable ntpd.service 2018-02-20T12:56:21Z DEBUG Process finished, return code=0