[Freeipa-users] ipa replica install fails

Rajnesh Kumar Siwal rajnesh.siwal at gmail.com
Tue Feb 5 16:48:29 UTC 2013


Both of these replica are in the same network.
I have disabled the iptables on both
Selinux disable.
still the output of kinit admin is the same
kinit: Cannot contact any KDC for realm

strace output attached.


On Tue, Feb 5, 2013 at 9:45 PM, Rajnesh Kumar Siwal
<rajnesh.siwal at gmail.com> wrote:
> Last time the installation of replica failed. So this is second time I
> did it (The logs in the mail are from the second time after I
> uninstalled the ipa2).
>
> After installing the replica, I restarted IPA and failed to start the KDC too.
> So, kinit admin is now failing.
> ---------------------------------------------------------------------
>
> [root at ipa2 log]# klist -ket /etc/named.keytab
> Keytab name: WRFILE:/etc/named.keytab
> KVNO Timestamp         Principal
> ---- ----------------- --------------------------------------------------------
>    2 02/05/13 14:30:26 DNS/ipa2.xyz.dmz at XYZ.DMZ (aes256-cts-hmac-sha1-96)
>    2 02/05/13 14:30:26 DNS/ipa2.xyz.dmz at XYZ.DMZ (aes128-cts-hmac-sha1-96)
>    2 02/05/13 14:30:26 DNS/ipa2.xyz.dmz at XYZ.DMZ (des3-cbc-sha1)
>    2 02/05/13 14:30:26 DNS/ipa2.xyz.dmz at XYZ.DMZ (arcfour-hmac)
> [root at ipa2 log]# kinit -kt DNS/ipa2.xyz.dmz at XYZ.DMZ
> kinit: Cannot contact any KDC for realm 'XYZ.DMZ' while getting
> initial credentials
> ---------------------------------------------------------------------------------------------------------------
>
> On Tue, Feb 5, 2013 at 8:15 PM, Rajnesh Kumar Siwal
> <rajnesh.siwal at gmail.com> wrote:
>> Finally , I installed it with "--skip-conncheck":-
>> Now DNS fails to start.
>> I tried ipa-dns-install too:-
>>
>> [root at ipa2 log]# ipa-dns-install
>> The log file for this installation can be found in
>> /var/log/ipaserver-install.log
>> ==============================================================================
>> This program will setup DNS for the IPA Server.
>>
>> This includes:
>>   * Configure DNS (bind)
>>
>> To accept the default shown in brackets, press the Enter key.
>> Existing BIND configuration detected, overwrite? [no]: yes
>> DNS is already configured in this IPA server.
>> [root at ipa2 log]# /etc/init.d/ipa status
>> Directory Service: RUNNING
>> KDC Service: RUNNING
>> KPASSWD Service: RUNNING
>> DNS Service: STOPPED
>> MEMCACHE Service: RUNNING
>> HTTP Service: RUNNING
>> CA Service: RUNNING
>> [root at ipa2 log]# /etc/init.d/named restart
>> Stopping named:                                            [  OK  ]
>> Starting named:                                            [FAILED]
>>
>> ---------------------------------------------------------------------------------------------
>> DNS logs :-
>> Feb  5 09:40:19 ipa2 named[19873]:
>> ----------------------------------------------------
>> Feb  5 09:40:19 ipa2 named[19873]: BIND 9 is maintained by Internet
>> Systems Consortium,
>> Feb  5 09:40:19 ipa2 named[19873]: Inc. (ISC), a non-profit 501(c)(3)
>> public-benefit
>> Feb  5 09:40:19 ipa2 named[19873]: corporation.  Support and training
>> for BIND 9 are
>> Feb  5 09:40:19 ipa2 named[19873]: available at https://www.isc.org/support
>> Feb  5 09:40:19 ipa2 named[19873]:
>> ----------------------------------------------------
>> Feb  5 09:40:19 ipa2 named[19873]: adjusted limit on open files from
>> 102400 to 1048576
>> Feb  5 09:40:19 ipa2 named[19873]: found 2 CPUs, using 2 worker threads
>> Feb  5 09:40:19 ipa2 named[19873]: using up to 4096 sockets
>> Feb  5 09:40:19 ipa2 named[19873]: loading configuration from '/etc/named.conf'
>> Feb  5 09:40:19 ipa2 named[19873]: using default UDP/IPv4 port range:
>> [1024, 65535]
>> Feb  5 09:40:19 ipa2 named[19873]: using default UDP/IPv6 port range:
>> [1024, 65535]
>> Feb  5 09:40:19 ipa2 named[19873]: listening on IPv6 interfaces, port 53
>> Feb  5 09:40:19 ipa2 named[19873]: listening on IPv4 interface lo, 127.0.0.1#53
>> Feb  5 09:40:19 ipa2 named[19873]: listening on IPv4 interface eth0,
>> 172.31.254.205#53
>> Feb  5 09:40:19 ipa2 named[19873]: generating session key for dynamic DNS
>> Feb  5 09:40:19 ipa2 named[19873]: sizing zone task pool based on 6 zones
>> Feb  5 09:40:19 ipa2 named[19873]: set up managed keys zone for view
>> _default, file 'dynamic/managed-keys.bind'
>> Feb  5 09:40:19 ipa2 named[19873]: GSSAPI Error: Unspecified GSS
>> failure.  Minor code may provide more information (Mutual
>> authentication failed)
>> Feb  5 09:40:19 ipa2 named[19873]: bind to LDAP server failed: Local error
>> Feb  5 09:40:19 ipa2 named[19873]: loading configuration: failure
>> Feb  5 09:40:19 ipa2 named[19873]: exiting (due to fatal error)
>> Feb  5 09:40:28 ipa2 kernel: IN=eth0 OUT=
>> MAC=ff:ff:ff:ff:ff:ff:00:22:6b:12:99:bc:08:00 SRC=0.0.0.0
>> DST=255.255.255.255 LEN=328 TOS=0x00 PREC=0x00 TTL=60 ID=0 PROTO=UDP
>> SPT=68 DPT=67 LEN=308
>> [root at ipa2 log]# klist
>> Ticket cache: FILE:/tmp/krb5cc_0
>> Default principal: admin at XYZ.DMZ
>> Valid starting     Expires            Service principal
>> 02/05/13 14:32:56  02/06/13 14:32:24  krbtgt/XYZ.DMZ at XYZ.DMZ
>> 02/05/13 14:33:16  02/06/13 14:31:34  ldap/ipa2.xyz.dmz at XYZ.DMZ
>>
>>
>>
>> On Tue, Feb 5, 2013 at 7:45 PM, Rajnesh Kumar Siwal
>> <rajnesh.siwal at gmail.com> wrote:
>>> Hi Rob,
>>>
>>> Thanks for the quick reply.
>>> I tried logging iptables in the replica also, but no log for dropped packet :-
>>> I would appreciate if you could please let me know what these login actually do.
>>> 1. Looks to me as getting tgt for admin
>>> 2. Is it trying to login though ssh to ipa1 server ?
>>> ----------------------------------------------------------------------
>>> Get credentials to log in to remote master
>>>  admin at XYZ.DMZ password:
>>>
>>>  Execute check on remote master
>>>  admin at ipa1.xyz.dmz's password:
>>> ----------------------------------------------------------------------
>>>
>>> SELINUX is disabled at both the ends.
>>>
>>> Is there any other log file that may suggest something.
>>> It would be great if we could figure out whats the cause of the error.
>>> -----------------------------------------------------------------------------------------------------------------------
>>>
>>> On Tue, Feb 5, 2013 at 7:35 PM, Rob Crittenden <rcritten at redhat.com> wrote:
>>>> Rajnesh Kumar Siwal wrote:
>>>>>
>>>>> We are trying to setup the IPA replication but it says "Connection
>>>>> check failed!".
>>>>> We disabled the firewall and found the same result.
>>>>>
>>>>>
>>>>> -----------------------------------------------------------------------------------------------------------------------
>>>>> [root at ipa2 /]# ipa-replica-install -d --setup-ca --setup-dns
>>>>> --forwarder 64.71.0.60 /var/lib/ipa/replica-info-ipa2.xyz.dmz.gpg
>>>>> ipa         : DEBUG    /usr/sbin/ipa-replica-install was invoked with
>>>>> argument "/var/lib/ipa/replica-info-ipa2.xyz.dmz.gpg" and options:
>>>>> {'no_forwarders': False, 'conf_ssh': False, 'conf_sshd': False,
>>>>> 'ui_redirect': True, 'reverse_zone': None, 'trust_sshfp': False,
>>>>> 'unattended': False, 'no_host_dns': False, 'ip_address': None,
>>>>> 'no_reverse': False, 'setup_dns': True, 'create_sshfp': True,
>>>>> 'setup_ca': True, 'forwarders': [CheckedIPAddress('64.71.0.60')],
>>>>> 'debug': True, 'conf_ntp': True, 'skip_conncheck': False}
>>>>> ipa         : DEBUG    Loading Index file from
>>>>> '/var/lib/ipa-client/sysrestore/sysrestore.index'
>>>>> ipa         : DEBUG    Loading StateFile from
>>>>> '/var/lib/ipa/sysrestore/sysrestore.state'
>>>>> ipa         : DEBUG    Loading Index file from
>>>>> '/var/lib/ipa/sysrestore/sysrestore.index'
>>>>> Directory Manager (existing master) password:
>>>>>
>>>>> ipa         : DEBUG    args=/usr/bin/gpg --batch --homedir
>>>>> /tmp/tmpRGaqDpipa/ipa-A3XOq7/.gnupg --passphrase-fd 0 --yes --no-tty
>>>>> -o /tmp/tmpRGaqDpipa/files.tar -d
>>>>> /var/lib/ipa/replica-info-ipa2.xyz.dmz.gpg
>>>>> ipa         : DEBUG    stdout=
>>>>> ipa         : DEBUG    stderr=gpg: WARNING: unsafe permissions on
>>>>> homedir `/tmp/tmpRGaqDpipa/ipa-A3XOq7/.gnupg'
>>>>> gpg: keyring `/tmp/tmpRGaqDpipa/ipa-A3XOq7/.gnupg/secring.gpg' created
>>>>> gpg: keyring `/tmp/tmpRGaqDpipa/ipa-A3XOq7/.gnupg/pubring.gpg' created
>>>>> gpg: 3DES encrypted data
>>>>> gpg: encrypted with 1 passphrase
>>>>> gpg: WARNING: message was not integrity protected
>>>>>
>>>>> ipa         : DEBUG    args=tar xf /tmp/tmpRGaqDpipa/files.tar -C
>>>>> /tmp/tmpRGaqDpipa
>>>>> ipa         : DEBUG    stdout=
>>>>> ipa         : DEBUG    stderr=
>>>>> Run connection check to master
>>>>> Check connection from replica to remote master 'ipa1.xyz.dmz':
>>>>>     Directory Service: Unsecure port (389): OK
>>>>>     Directory Service: Secure port (636): OK
>>>>>     Kerberos KDC: TCP (88): OK
>>>>>     Kerberos Kpasswd: TCP (464): OK
>>>>>     HTTP Server: Unsecure port (80): OK
>>>>>     HTTP Server: Secure port (443): OK
>>>>>     PKI-CA: Directory Service port (7389): OK
>>>>>
>>>>> The following list of ports use UDP protocol and would need to be
>>>>> checked manually:
>>>>>     Kerberos KDC: UDP (88): SKIPPED
>>>>>     Kerberos Kpasswd: UDP (464): SKIPPED
>>>>>
>>>>> Connection from replica to master is OK.
>>>>> Start listening on required ports for remote master check
>>>>> Get credentials to log in to remote master
>>>>> admin at XYZ.DMZ password:
>>>>>
>>>>> Execute check on remote master
>>>>> admin at ipa1.xyz.dmz's password:
>>>>>
>>>>> Remote master check failed with following error message(s):
>>>>>
>>>>> ipa         : DEBUG    args=/usr/sbin/ipa-replica-conncheck --master
>>>>> ipa1.xyz.dmz --auto-master-check --realm XYZ.DMZ --principal admin
>>>>> --hostname ipa2.xyz.dmz --check-ca
>>>>> Connection check failed!
>>>>> Please fix your network settings according to error messages above.
>>>>> If the check results are not valid it can be skipped with
>>>>> --skip-conncheck parameter.
>>>>>
>>>>> --------------------------------------------------------------------------------------------------------------------------------------------------------------
>>>>> Please suggest
>>>>
>>>>
>>>> Each server has its own iptables configuration.
>>>>
>>>> The test from the replica to the master succeeded. What failed is the
>>>> connection test from the master to the replica, so I'd look at the iptables
>>>> configuration on the replica machine.
>>>>
>>>> If that turns out ok it could be a false positive. You can add the
>>>> --skip-conncheck to the ipa-replica-install command to skip this test.
>>>>
>>>> rob
>>>
>>>
>>>
>>> --
>>> Regards,
>>> Rajnesh Kumar Siwal
>>
>>
>>
>> --
>> Regards,
>> Rajnesh Kumar Siwal
>
>
>
> --
> Regards,
> Rajnesh Kumar Siwal



-- 
Regards,
Rajnesh Kumar Siwal
-------------- next part --------------
[root at ipa2 log]# /etc/init.d/iptables stop
iptables: Flushing firewall rules:                         [  OK  ]
iptables: Setting chains to policy ACCEPT: filter          [  OK  ]
iptables: Unloading modules:                               [  OK  ]
[root at ipa2 log]# setenforce 0
[root at ipa2 log]# kinit admin
kinit: Cannot contact any KDC for realm 'XYZ.DMZ' while getting initial credentials
[root at ipa2 log]# statce kinit admin
-bash: statce: command not found
[root at ipa2 log]# strace kinit admin
execve("/usr/bin/kinit", ["kinit", "admin"], [/* 22 vars */]) = 0
brk(0)                                  = 0x7fa389df2000
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa3881ad000
access("/etc/ld.so.preload", R_OK)      = -1 ENOENT (No such file or directory)
open("/etc/ld.so.cache", O_RDONLY)      = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=32166, ...}) = 0
mmap(NULL, 32166, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7fa3881a5000
close(3)                                = 0
open("/usr/lib64/libkadm5srv_mit.so.8", O_RDONLY) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\340n\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=118512, ...}) = 0
mmap(NULL, 2255256, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7fa387d68000
mprotect(0x7fa387d84000, 2093056, PROT_NONE) = 0
mmap(0x7fa387f83000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1b000) = 0x7fa387f83000
mmap(0x7fa387f85000, 39320, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fa387f85000
close(3)                                = 0
open("/usr/lib64/libkdb5.so.5", O_RDONLY) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\340?\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=72888, ...}) = 0
mmap(NULL, 2168096, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7fa387b56000
mprotect(0x7fa387b67000, 2093056, PROT_NONE) = 0
mmap(0x7fa387d66000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x10000) = 0x7fa387d66000
close(3)                                = 0
open("/lib64/libgssrpc.so.4", O_RDONLY) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\20X\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=131384, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa3881a4000
mmap(NULL, 2226952, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7fa387936000
mprotect(0x7fa387954000, 2097152, PROT_NONE) = 0
mmap(0x7fa387b54000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1e000) = 0x7fa387b54000
close(3)                                = 0
open("/lib64/libgssapi_krb5.so.2", O_RDONLY) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0 \236\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=269472, ...}) = 0
mmap(NULL, 2365152, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7fa3876f4000
mprotect(0x7fa387733000, 2097152, PROT_NONE) = 0
mmap(0x7fa387933000, 12288, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x3f000) = 0x7fa387933000
close(3)                                = 0
open("/lib64/libkrb5.so.3", O_RDONLY)   = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\20\246\1\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=912944, ...}) = 0
mmap(NULL, 3008864, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7fa387415000
mprotect(0x7fa3874e9000, 2097152, PROT_NONE) = 0
mmap(0x7fa3876e9000, 45056, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0xd4000) = 0x7fa3876e9000
close(3)                                = 0
open("/lib64/libk5crypto.so.3", O_RDONLY) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\300G\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=178952, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa3881a3000
mmap(NULL, 2275296, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7fa3871e9000
mprotect(0x7fa387213000, 2093056, PROT_NONE) = 0
mmap(0x7fa387412000, 12288, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x29000) = 0x7fa387412000
close(3)                                = 0
open("/lib64/libcom_err.so.2", O_RDONLY) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\360\23\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=14664, ...}) = 0
mmap(NULL, 2109872, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7fa386fe5000
mprotect(0x7fa386fe8000, 2093056, PROT_NONE) = 0
mmap(0x7fa3871e7000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x2000) = 0x7fa3871e7000
close(3)                                = 0
open("/lib64/libkrb5support.so.0", O_RDONLY) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\360(\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=43712, ...}) = 0
mmap(NULL, 2139184, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7fa386dda000
mprotect(0x7fa386de4000, 2093056, PROT_NONE) = 0
mmap(0x7fa386fe3000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x9000) = 0x7fa386fe3000
close(3)                                = 0
open("/lib64/libkeyutils.so.1", O_RDONLY) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\360\v\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=10192, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa3881a2000
mmap(NULL, 2105424, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7fa386bd7000
mprotect(0x7fa386bd9000, 2093056, PROT_NONE) = 0
mmap(0x7fa386dd8000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1000) = 0x7fa386dd8000
close(3)                                = 0
open("/lib64/libresolv.so.2", O_RDONLY) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\00009\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=110960, ...}) = 0
mmap(NULL, 2202248, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7fa3869bd000
mprotect(0x7fa3869d3000, 2097152, PROT_NONE) = 0
mmap(0x7fa386bd3000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x16000) = 0x7fa386bd3000
mmap(0x7fa386bd5000, 6792, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fa386bd5000
close(3)                                = 0
open("/lib64/libselinux.so.1", O_RDONLY) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0PX\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=122040, ...}) = 0
mmap(NULL, 2221912, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7fa38679e000
mprotect(0x7fa3867bb000, 2093056, PROT_NONE) = 0
mmap(0x7fa3869ba000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1c000) = 0x7fa3869ba000
mmap(0x7fa3869bc000, 1880, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fa3869bc000
close(3)                                = 0
open("/lib64/libdl.so.2", O_RDONLY)     = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\340\r\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=19536, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa3881a1000
mmap(NULL, 2109696, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7fa38659a000
mprotect(0x7fa38659c000, 2097152, PROT_NONE) = 0
mmap(0x7fa38679c000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x2000) = 0x7fa38679c000
close(3)                                = 0
open("/lib64/libc.so.6", O_RDONLY)      = 3
read(3, "\177ELF\2\1\1\3\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\360\355\1\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=1916528, ...}) = 0
mmap(NULL, 3745960, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7fa386207000
mprotect(0x7fa386390000, 2097152, PROT_NONE) = 0
mmap(0x7fa386590000, 20480, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x189000) = 0x7fa386590000
mmap(0x7fa386595000, 18600, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fa386595000
close(3)                                = 0
open("/lib64/libpthread.so.0", O_RDONLY) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0`\\\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=142464, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa3881a0000
mmap(NULL, 2212768, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7fa385fea000
mprotect(0x7fa386001000, 2097152, PROT_NONE) = 0
mmap(0x7fa386201000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x17000) = 0x7fa386201000
mmap(0x7fa386203000, 13216, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fa386203000
close(3)                                = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa38819f000
mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa38819d000
arch_prctl(ARCH_SET_FS, 0x7fa38819d7c0) = 0
mprotect(0x7fa386201000, 4096, PROT_READ) = 0
mprotect(0x7fa386590000, 16384, PROT_READ) = 0
mprotect(0x7fa38679c000, 4096, PROT_READ) = 0
mprotect(0x7fa3869ba000, 4096, PROT_READ) = 0
mprotect(0x7fa386bd3000, 4096, PROT_READ) = 0
mprotect(0x7fa386dd8000, 4096, PROT_READ) = 0
mprotect(0x7fa386fe3000, 4096, PROT_READ) = 0
mprotect(0x7fa3871e7000, 4096, PROT_READ) = 0
mprotect(0x7fa387412000, 8192, PROT_READ) = 0
mprotect(0x7fa3876e9000, 36864, PROT_READ) = 0
mprotect(0x7fa387933000, 4096, PROT_READ) = 0
mprotect(0x7fa387b54000, 4096, PROT_READ) = 0
mprotect(0x7fa387d66000, 4096, PROT_READ) = 0
mprotect(0x7fa387f83000, 4096, PROT_READ) = 0
mprotect(0x7fa3883b5000, 4096, PROT_READ) = 0
mprotect(0x7fa3881ae000, 4096, PROT_READ) = 0
munmap(0x7fa3881a5000, 32166)           = 0
set_tid_address(0x7fa38819da90)         = 21248
set_robust_list(0x7fa38819daa0, 0x18)   = 0
futex(0x7fffa0ede8fc, FUTEX_WAKE_PRIVATE, 1) = 0
futex(0x7fffa0ede8fc, FUTEX_WAIT_BITSET_PRIVATE|FUTEX_CLOCK_REALTIME, 1, NULL, 7fa38819d7c0) = -1 EAGAIN (Resource temporarily unavailable)
rt_sigaction(SIGRTMIN, {0x7fa385fefae0, [], SA_RESTORER|SA_SIGINFO, 0x7fa385ff9500}, NULL, 8) = 0
rt_sigaction(SIGRT_1, {0x7fa385fefb70, [], SA_RESTORER|SA_RESTART|SA_SIGINFO, 0x7fa385ff9500}, NULL, 8) = 0
rt_sigprocmask(SIG_UNBLOCK, [RTMIN RT_1], NULL, 8) = 0
getrlimit(RLIMIT_STACK, {rlim_cur=10240*1024, rlim_max=RLIM_INFINITY}) = 0
statfs("/selinux", {f_type=0xf97cff8c, f_bsize=4096, f_blocks=0, f_bfree=0, f_bavail=0, f_files=0, f_ffree=0, f_fsid={0, 0}, f_namelen=255, f_frsize=4096}) = 0
brk(0)                                  = 0x7fa389df2000
brk(0x7fa389e13000)                     = 0x7fa389e13000
ioctl(0, SNDCTL_TMR_TIMEBASE or TCGETS, {B38400 opost isig icanon echo ...}) = 0
ioctl(1, SNDCTL_TMR_TIMEBASE or TCGETS, {B38400 opost isig icanon echo ...}) = 0
ioctl(2, SNDCTL_TMR_TIMEBASE or TCGETS, {B38400 opost isig icanon echo ...}) = 0
futex(0x7fa386fe42e8, FUTEX_WAKE_PRIVATE, 2147483647) = 0
futex(0x7fa386fe4280, FUTEX_WAKE_PRIVATE, 2147483647) = 0
futex(0x7fa3876f3200, FUTEX_WAKE_PRIVATE, 2147483647) = 0
futex(0x7fa3876f3600, FUTEX_WAKE_PRIVATE, 2147483647) = 0
stat("/etc/krb5.conf", {st_mode=S_IFREG|0644, st_size=612, ...}) = 0
open("/etc/krb5.conf", O_RDONLY)        = 3
fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
fstat(3, {st_mode=S_IFREG|0644, st_size=612, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa3881ac000
read(3, "[logging]\n default = FILE:/var/l"..., 4096) = 612
read(3, "", 4096)                       = 0
close(3)                                = 0
munmap(0x7fa3881ac000, 4096)            = 0
open("/dev/urandom", O_RDONLY)          = 3
fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
fstat(3, {st_mode=S_IFCHR|0666, st_rdev=makedev(1, 9), ...}) = 0
read(3, "q3e\364\177\241_\34\357\343\325%\33\3072\203:\212\346\372", 20) = 20
close(3)                                = 0
futex(0x7fa3874142d0, FUTEX_WAKE_PRIVATE, 2147483647) = 0
getuid()                                = 0
open("/usr/lib64/krb5/plugins/preauth", O_RDONLY|O_NONBLOCK|O_DIRECTORY|O_CLOEXEC) = 3
fcntl(3, F_GETFD)                       = 0x1 (flags FD_CLOEXEC)
getdents(3, /* 4 entries */, 32768)     = 128
stat("/usr/lib64/krb5/plugins/preauth/pkinit.so", {st_mode=S_IFREG|0755, st_size=116144, ...}) = 0
futex(0x7fa38679d0ec, FUTEX_WAKE_PRIVATE, 2147483647) = 0
open("/usr/lib64/krb5/plugins/preauth/pkinit.so", O_RDONLY) = 4
read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\240d\0\0\0\0\0\0"..., 832) = 832
fstat(4, {st_mode=S_IFREG|0755, st_size=116144, ...}) = 0
mmap(NULL, 2211544, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fa385dce000
mprotect(0x7fa385de8000, 2097152, PROT_NONE) = 0
mmap(0x7fa385fe8000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x1a000) = 0x7fa385fe8000
close(4)                                = 0
open("/etc/ld.so.cache", O_RDONLY)      = 4
fstat(4, {st_mode=S_IFREG|0644, st_size=32166, ...}) = 0
mmap(NULL, 32166, PROT_READ, MAP_PRIVATE, 4, 0) = 0x7fa3881a5000
close(4)                                = 0
open("/usr/lib64/libcrypto.so.10", O_RDONLY) = 4
read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\312\5\0\0\0\0\0"..., 832) = 832
fstat(4, {st_mode=S_IFREG|0755, st_size=1662832, ...}) = 0
mmap(NULL, 3773576, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fa385a34000
mprotect(0x7fa385ba8000, 2093056, PROT_NONE) = 0
mmap(0x7fa385da7000, 143360, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x173000) = 0x7fa385da7000
mmap(0x7fa385dca000, 13448, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fa385dca000
close(4)                                = 0
open("/lib64/libz.so.1", O_RDONLY)      = 4
read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0000\37\0\0\0\0\0\0"..., 832) = 832
fstat(4, {st_mode=S_IFREG|0755, st_size=88520, ...}) = 0
mmap(NULL, 2183696, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fa38581e000
mprotect(0x7fa385833000, 2093056, PROT_NONE) = 0
mmap(0x7fa385a32000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x14000) = 0x7fa385a32000
close(4)                                = 0
mprotect(0x7fa385a32000, 4096, PROT_READ) = 0
mprotect(0x7fa385da7000, 102400, PROT_READ) = 0
mprotect(0x7fa385fe8000, 4096, PROT_READ) = 0
munmap(0x7fa3881a5000, 32166)           = 0
stat("/usr/lib64/krb5/plugins/preauth/encrypted_challenge.so", {st_mode=S_IFREG|0755, st_size=10616, ...}) = 0
open("/usr/lib64/krb5/plugins/preauth/encrypted_challenge.so", O_RDONLY) = 4
read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@\v\0\0\0\0\0\0"..., 832) = 832
fstat(4, {st_mode=S_IFREG|0755, st_size=10616, ...}) = 0
mmap(NULL, 2105704, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fa38561b000
mprotect(0x7fa38561d000, 2093056, PROT_NONE) = 0
mmap(0x7fa38581c000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x1000) = 0x7fa38581c000
close(4)                                = 0
mprotect(0x7fa38581c000, 4096, PROT_READ) = 0
getdents(3, /* 0 entries */, 32768)     = 0
close(3)                                = 0
open("/proc/sys/crypto/fips_enabled", O_RDONLY) = 3
read(3, "0\n", 2)                       = 2
close(3)                                = 0
open("/etc/localtime", O_RDONLY)        = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=618, ...}) = 0
fstat(3, {st_mode=S_IFREG|0644, st_size=618, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa3881ac000
read(3, "TZif2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\1\0\0\0\31"..., 4096) = 618
lseek(3, -362, SEEK_CUR)                = 256
read(3, "TZif2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\1\0\0\0\31"..., 4096) = 362
close(3)                                = 0
munmap(0x7fa3881ac000, 4096)            = 0
open("/usr/lib64/krb5/plugins/libkrb5", O_RDONLY|O_NONBLOCK|O_DIRECTORY|O_CLOEXEC) = 3
brk(0x7fa389e35000)                     = 0x7fa389e35000
getdents(3, /* 3 entries */, 32768)     = 96
stat("/usr/lib64/krb5/plugins/libkrb5/sssd_krb5_locator_plugin.so", {st_mode=S_IFREG|0755, st_size=10888, ...}) = 0
open("/usr/lib64/krb5/plugins/libkrb5/sssd_krb5_locator_plugin.so", O_RDONLY) = 4
read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@\f\0\0\0\0\0\0"..., 832) = 832
fstat(4, {st_mode=S_IFREG|0755, st_size=10888, ...}) = 0
mmap(NULL, 2106120, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fa385418000
mprotect(0x7fa38541a000, 2097152, PROT_NONE) = 0
mmap(0x7fa38561a000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x2000) = 0x7fa38561a000
close(4)                                = 0
getdents(3, /* 0 entries */, 32768)     = 0
close(3)                                = 0
open("/var/lib/sss/pubconf/kdcinfo.XYZ.DMZ", O_RDONLY) = -1 ENOENT (No such file or directory)
socket(PF_NETLINK, SOCK_RAW, 0)         = 3
bind(3, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
getsockname(3, {sa_family=AF_NETLINK, pid=21248, groups=00000000}, [12]) = 0
sendto(3, "\24\0\0\0\26\0\1\3\3776\21Q\0\0\0\0\0\0\0\0", 20, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
recvmsg(3, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"0\0\0\0\24\0\2\0\3776\21Q\0S\0\0\2\10\200\376\1\0\0\0\10\0\1\0\177\0\0\1"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 108
recvmsg(3, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\3776\21Q\0S\0\0\n\200\200\376\1\0\0\0\24\0\1\0\0\0\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(3, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0\3776\21Q\0S\0\0\0\0\0\0\1\0\0\0\24\0\1\0\0\0\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
close(3)                                = 0
socket(PF_FILE, SOCK_STREAM|SOCK_CLOEXEC|SOCK_NONBLOCK, 0) = 3
connect(3, {sa_family=AF_FILE, path="/var/run/nscd/socket"}, 110) = -1 ENOENT (No such file or directory)
close(3)                                = 0
socket(PF_FILE, SOCK_STREAM|SOCK_CLOEXEC|SOCK_NONBLOCK, 0) = 3
connect(3, {sa_family=AF_FILE, path="/var/run/nscd/socket"}, 110) = -1 ENOENT (No such file or directory)
close(3)                                = 0
open("/etc/nsswitch.conf", O_RDONLY)    = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=1698, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa3881ac000
read(3, "#\n# /etc/nsswitch.conf\n#\n# An ex"..., 4096) = 1698
read(3, "", 4096)                       = 0
close(3)                                = 0
munmap(0x7fa3881ac000, 4096)            = 0
open("/etc/host.conf", O_RDONLY)        = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=9, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa3881ac000
read(3, "multi on\n", 4096)             = 9
read(3, "", 4096)                       = 0
close(3)                                = 0
munmap(0x7fa3881ac000, 4096)            = 0
futex(0x7fa386598384, FUTEX_WAKE_PRIVATE, 2147483647) = 0
open("/etc/resolv.conf", O_RDONLY)      = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=76, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa3881ac000
read(3, "search xyz.dmz\n#nameserv"..., 4096) = 76
read(3, "", 4096)                       = 0
close(3)                                = 0
munmap(0x7fa3881ac000, 4096)            = 0
open("/etc/ld.so.cache", O_RDONLY)      = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=32166, ...}) = 0
mmap(NULL, 32166, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7fa3881a5000
close(3)                                = 0
open("/lib64/libnss_files.so.2", O_RDONLY) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\360!\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=65928, ...}) = 0
mmap(NULL, 2151824, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7fa38520a000
mprotect(0x7fa385216000, 2097152, PROT_NONE) = 0
mmap(0x7fa385416000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0xc000) = 0x7fa385416000
close(3)                                = 0
mprotect(0x7fa385416000, 4096, PROT_READ) = 0
munmap(0x7fa3881a5000, 32166)           = 0
open("/etc/hosts", O_RDONLY|O_CLOEXEC)  = 3
fcntl(3, F_GETFD)                       = 0x1 (flags FD_CLOEXEC)
fstat(3, {st_mode=S_IFREG|0644, st_size=240, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa3881ac000
read(3, "127.0.0.1   localhost localhost."..., 4096) = 240
read(3, "", 4096)                       = 0
close(3)                                = 0
munmap(0x7fa3881ac000, 4096)            = 0
open("/var/lib/sss/pubconf/kdcinfo.XYZ.DMZ", O_RDONLY) = -1 ENOENT (No such file or directory)
socket(PF_NETLINK, SOCK_RAW, 0)         = 3
bind(3, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
getsockname(3, {sa_family=AF_NETLINK, pid=21248, groups=00000000}, [12]) = 0
sendto(3, "\24\0\0\0\26\0\1\3\3776\21Q\0\0\0\0\0\0\0\0", 20, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
recvmsg(3, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"0\0\0\0\24\0\2\0\3776\21Q\0S\0\0\2\10\200\376\1\0\0\0\10\0\1\0\177\0\0\1"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 108
recvmsg(3, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\3776\21Q\0S\0\0\n\200\200\376\1\0\0\0\24\0\1\0\0\0\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(3, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0\3776\21Q\0S\0\0\0\0\0\0\1\0\0\0\24\0\1\0\0\0\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
close(3)                                = 0
open("/etc/hosts", O_RDONLY|O_CLOEXEC)  = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=240, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa3881ac000
read(3, "127.0.0.1   localhost localhost."..., 4096) = 240
read(3, "", 4096)                       = 0
close(3)                                = 0
munmap(0x7fa3881ac000, 4096)            = 0
socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 3
fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
connect(3, {sa_family=AF_INET, sin_port=htons(88), sin_addr=inet_addr("172.31.254.205")}, 16) = 0
sendto(3, "j\201\2670\201\264\241\3\2\1\5\242\3\2\1\n\243\0160\f0\n\241\4\2\2\0\225\242\2\4\0"..., 186, 0, NULL, 0) = 186
poll([{fd=3, events=POLLIN}], 1, 1000)  = 1 ([{fd=3, revents=POLLERR}])
recvfrom(3, 0x7fa389e119b0, 4096, 0, 0, 0) = -1 ECONNREFUSED (Connection refused)
close(3)                                = 0
socket(PF_INET, SOCK_STREAM, IPPROTO_IP) = 3
fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
ioctl(3, FIONBIO, [1])                  = 0
setsockopt(3, SOL_SOCKET, SO_LINGER, {onoff=0, linger=0}, 8) = 0
connect(3, {sa_family=AF_INET, sin_port=htons(88), sin_addr=inet_addr("172.31.254.205")}, 16) = -1 EINPROGRESS (Operation now in progress)
poll([{fd=3, events=POLLIN|POLLOUT}], 1, 1000) = 1 ([{fd=3, revents=POLLIN|POLLERR|POLLHUP}])
close(3)                                = 0
close(4294967295)                       = -1 EBADF (Bad file descriptor)
write(2, "kinit: Cannot contact any KDC fo"..., 58kinit: Cannot contact any KDC for realm 'XYZ.DMZ' ) = 58
write(2, "while getting initial credential"..., 33while getting initial credentials) = 33
write(2, "\n", 1
)                       = 1
munmap(0x7fa385dce000, 2211544)         = 0
munmap(0x7fa385a34000, 3773576)         = 0
munmap(0x7fa38581e000, 2183696)         = 0
munmap(0x7fa38561b000, 2105704)         = 0
munmap(0x7fa385418000, 2106120)         = 0
exit_group(1)                           = ?



More information about the Freeipa-users mailing list