[Freeipa-users] FreeIPA (Add Replica fails on GSSAPI)

Devin Acosta linuxguru.co at gmail.com
Tue Jul 12 19:34:46 UTC 2016


I am trying to add a 4th replica to my FreeIPA installation. I am running
the latest CentOS 7.2 (full updates) and i have tried multiple times and
fails every time in same location. When it fails I remove the replication
agreements and try again and keeps failing in same location.


[root at ipa03-aws centos]# ipa-replica-install
replica-info-ipa03-aws.rsinc.local.gpg
WARNING: conflicting time&date synchronization service 'chronyd' will
be disabled in favor of ntpd

Directory Manager (existing master) password:

Run connection check to master
Check connection from replica to remote master 'ipa01-aws.rsinc.local':
   Directory Service: Unsecure port (389): OK
   Directory Service: Secure port (636): OK
   Kerberos KDC: TCP (88): OK
   Kerberos Kpasswd: TCP (464): OK
   HTTP Server: Unsecure port (80): OK
   HTTP Server: Secure port (443): OK

The following list of ports use UDP protocol and would need to be
checked manually:
   Kerberos KDC: UDP (88): SKIPPED
   Kerberos Kpasswd: UDP (464): SKIPPED

Connection from replica to master is OK.
Start listening on required ports for remote master check
Get credentials to log in to remote master
admin at RSINC.LOCAL password:

Check SSH connection to remote master
Execute check on remote master
Check connection from master to remote replica 'ipa03-aws.rsinc.local':
   Directory Service: Unsecure port (389): OK
   Directory Service: Secure port (636): OK
   Kerberos KDC: TCP (88): OK
   Kerberos KDC: UDP (88): OK
   Kerberos Kpasswd: TCP (464): OK
   Kerberos Kpasswd: UDP (464): OK
   HTTP Server: Unsecure port (80): OK
   HTTP Server: Secure port (443): OK

Connection from master to replica is OK.

Connection check OK
Configuring NTP daemon (ntpd)
  [1/4]: stopping ntpd
  [2/4]: writing configuration
  [3/4]: configuring ntpd to start on boot
  [4/4]: starting ntpd
Done configuring NTP daemon (ntpd).
Configuring directory server (dirsrv). Estimated time: 1 minute
  [1/38]: creating directory server user
  [2/38]: creating directory server instance
  [3/38]: adding default schema
  [4/38]: enabling memberof plugin
  [5/38]: enabling winsync plugin
  [6/38]: configuring replication version plugin
  [7/38]: enabling IPA enrollment plugin
  [8/38]: enabling ldapi
  [9/38]: configuring uniqueness plugin
  [10/38]: configuring uuid plugin
  [11/38]: configuring modrdn plugin
  [12/38]: configuring DNS plugin
  [13/38]: enabling entryUSN plugin
  [14/38]: configuring lockout plugin
  [15/38]: creating indices
  [16/38]: enabling referential integrity plugin
  [17/38]: configuring ssl for ds instance
  [18/38]: configuring certmap.conf
  [19/38]: configure autobind for root
  [20/38]: configure new location for managed entries
  [21/38]: configure dirsrv ccache
  [22/38]: enable SASL mapping fallback
  [23/38]: restarting directory server
  [24/38]: setting up initial replication
Starting replication, please wait until this has completed.
Update in progress, 4 seconds elapsed
Update succeeded

  [25/38]: updating schema
  [26/38]: setting Auto Member configuration
  [27/38]: enabling S4U2Proxy delegation
  [28/38]: importing CA certificates from LDAP
  [29/38]: initializing group membership
  [30/38]: adding master entry
  [31/38]: initializing domain level
  [32/38]: configuring Posix uid/gid generation
  [33/38]: adding replication acis
  [34/38]: enabling compatibility plugin
  [35/38]: activating sidgen plugin
  [36/38]: activating extdom plugin
  [37/38]: tuning directory server
  [38/38]: configuring directory to start on boot
Done configuring directory server (dirsrv).
Configuring Kerberos KDC (krb5kdc). Estimated time: 30 seconds
  [1/8]: adding sasl mappings to the directory
  [2/8]: configuring KDC
  [3/8]: creating a keytab for the directory
  [4/8]: creating a keytab for the machine
  [5/8]: adding the password extension to the directory
  [6/8]: enable GSSAPI for replication
  [error] RuntimeError: One of the ldap service principals is missing.
Replication agreement cannot be converted.
Replication error message: Can't acquire busy replica
Your system may be partly configured.
Run /usr/sbin/ipa-server-install --uninstall to clean up.

ipa.ipapython.install.cli.install_tool(Replica): ERROR    One of the ldap
service principals is missing. Replication agreement cannot be converted.
Replication error message: Can't acquire busy replica

Please see attached file for the full log file.

Any help would be appreciated!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20160712/f3dccfc0/attachment.htm>
-------------- next part --------------
2016-07-12T18:50:11Z DEBUG Logging to /var/log/ipareplica-install.log
2016-07-12T18:50:11Z DEBUG ipa-replica-install was invoked with arguments ['replica-info-ipa03-aws.rsinc.local.gpg'] and options: {'no_dns_sshfp': None, 'skip_schema_check': None, 'no_ntp': None, 'setup_kra': None, 'ip_addresses': None, 'mkhomedir': None, 'setup_ca': None, 'no_pkinit': None, 'verbose': False, 'no_forwarders': None, 'ssh_trust_dns': None, 'setup_dns': None, 'no_reverse': None, 'reverse_zones': None, 'unattended': False, 'no_host_dns': None, 'no_sshd': None, 'no_ui_redirect': None, 'forwarders': None, 'skip_conncheck': None, 'no_ssh': None, 'quiet': False, 'no_dnssec_validation': None, 'log_file': None}
2016-07-12T18:50:11Z DEBUG IPA version 4.2.0-15.0.1.el7.centos.17
2016-07-12T18:50:11Z DEBUG Starting external process
2016-07-12T18:50:11Z DEBUG args='/usr/sbin/selinuxenabled'
2016-07-12T18:50:11Z DEBUG Process finished, return code=0
2016-07-12T18:50:11Z DEBUG stdout=
2016-07-12T18:50:11Z DEBUG stderr=
2016-07-12T18:50:11Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index'
2016-07-12T18:50:11Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:50:11Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:50:11Z DEBUG Starting external process
2016-07-12T18:50:11Z DEBUG args='/usr/sbin/httpd' '-t' '-D' 'DUMP_VHOSTS'
2016-07-12T18:50:11Z DEBUG Process finished, return code=0
2016-07-12T18:50:11Z DEBUG stdout=VirtualHost configuration:
*:8443                 ipa03-aws.rsinc.local (/etc/httpd/conf.d/nss.conf:83)

2016-07-12T18:50:11Z DEBUG stderr=
2016-07-12T18:50:11Z DEBUG Starting external process
2016-07-12T18:50:11Z DEBUG args='/bin/systemctl' 'is-enabled' 'chronyd.service'
2016-07-12T18:50:11Z DEBUG Process finished, return code=0
2016-07-12T18:50:11Z DEBUG stdout=enabled

2016-07-12T18:50:11Z DEBUG stderr=
2016-07-12T18:50:14Z DEBUG Starting external process
2016-07-12T18:50:14Z DEBUG args='/usr/bin/gpg-agent' '--batch' '--homedir' '/tmp/tmp34bUDTipa/ipa-MkvnMP/.gnupg' '--daemon' '/usr/bin/gpg' '--batch' '--homedir' '/tmp/tmp34bUDTipa/ipa-MkvnMP/.gnupg' '--passphrase-fd' '0' '--yes' '--no-tty' '-o' '/tmp/tmp34bUDTipa/files.tar' '-d' 'replica-info-ipa03-aws.rsinc.local.gpg'
2016-07-12T18:50:14Z DEBUG Process finished, return code=0
2016-07-12T18:50:14Z DEBUG Starting external process
2016-07-12T18:50:14Z DEBUG args='tar' 'xf' '/tmp/tmp34bUDTipa/files.tar' '-C' '/tmp/tmp34bUDTipa'
2016-07-12T18:50:14Z DEBUG Process finished, return code=0
2016-07-12T18:50:14Z DEBUG stdout=
2016-07-12T18:50:14Z DEBUG stderr=
2016-07-12T18:50:14Z DEBUG Installing replica file with version 40200 (0 means no version in prepared file).
2016-07-12T18:50:14Z DEBUG Check if ipa03-aws.rsinc.local is a primary hostname for localhost
2016-07-12T18:50:14Z DEBUG Primary hostname for localhost: ipa03-aws.rsinc.local
2016-07-12T18:50:14Z DEBUG Search DNS for ipa03-aws.rsinc.local
2016-07-12T18:50:14Z DEBUG Check if ipa03-aws.rsinc.local is not a CNAME
2016-07-12T18:50:15Z DEBUG Check reverse address of 10.40.0.242
2016-07-12T18:50:15Z DEBUG Found reverse name: ipa03-aws.rsinc.local
2016-07-12T18:50:15Z DEBUG importing all plugin modules in ipalib.plugins...
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.aci
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.automember
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.automount
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.baseldap
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.baseuser
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.batch
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.caacl
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.cert
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.certprofile
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.config
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.delegation
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.dns
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.domainlevel
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.group
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.hbacrule
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.hbacsvc
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.hbacsvcgroup
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.hbactest
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.host
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.hostgroup
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.idrange
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.idviews
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.internal
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.kerberos
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.krbtpolicy
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.migration
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.misc
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.netgroup
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.otpconfig
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.otptoken
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.otptoken_yubikey
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.passwd
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.permission
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.ping
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.pkinit
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.privilege
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.pwpolicy
2016-07-12T18:50:15Z DEBUG Starting external process
2016-07-12T18:50:15Z DEBUG args='klist' '-V'
2016-07-12T18:50:15Z DEBUG Process finished, return code=0
2016-07-12T18:50:15Z DEBUG stdout=Kerberos 5 version 1.13.2

2016-07-12T18:50:15Z DEBUG stderr=
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.radiusproxy
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.realmdomains
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.role
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.rpcclient
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.selfservice
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.selinuxusermap
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.server
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.service
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.servicedelegation
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.session
2016-07-12T18:50:15Z WARNING session memcached servers not running
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.stageuser
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.sudocmd
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.sudocmdgroup
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.sudorule
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.topology
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.trust
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.user
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.vault
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.virtual
2016-07-12T18:50:15Z DEBUG importing all plugin modules in ipaserver.plugins...
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.plugins.dogtag
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.plugins.join
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.plugins.ldap2
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.plugins.rabase
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.plugins.xmlserver
2016-07-12T18:50:15Z DEBUG importing all plugin modules in ipaserver.install.plugins...
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.adtrust
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.dns
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.update_nis
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.update_referint
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.update_services
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt
2016-07-12T18:50:15Z DEBUG SessionAuthManager.register: name=jsonserver_session_59557136
2016-07-12T18:50:15Z DEBUG SessionAuthManager.register: name=xmlserver_session_59559568
2016-07-12T18:50:15Z DEBUG Mounting ipaserver.rpcserver.jsonserver_kerb() at '/json'
2016-07-12T18:50:15Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:15Z DEBUG Mounting ipaserver.rpcserver.xmlserver_session() at '/session/xml'
2016-07-12T18:50:15Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:15Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:15Z DEBUG Mounting ipaserver.rpcserver.sync_token() at '/session/sync_token'
2016-07-12T18:50:15Z DEBUG Mounting ipaserver.rpcserver.xmlserver() at '/xml'
2016-07-12T18:50:15Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:15Z DEBUG Mounting ipaserver.rpcserver.jsonserver_session() at '/session/json'
2016-07-12T18:50:15Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:15Z DEBUG Mounting ipaserver.rpcserver.login_kerberos() at '/session/login_kerberos'
2016-07-12T18:50:15Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:16Z DEBUG Mounting ipaserver.rpcserver.login_password() at '/session/login_password'
2016-07-12T18:50:16Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:16Z DEBUG Mounting ipaserver.rpcserver.change_password() at '/session/change_password'
2016-07-12T18:50:16Z DEBUG Check if ipa01-aws.rsinc.local is a primary hostname for localhost
2016-07-12T18:50:16Z DEBUG Primary hostname for localhost: ipa01-aws.rsinc.local
2016-07-12T18:50:16Z DEBUG Search DNS for ipa01-aws.rsinc.local
2016-07-12T18:50:21Z DEBUG Check if ipa01-aws.rsinc.local is not a CNAME
2016-07-12T18:50:21Z DEBUG Check reverse address of 10.10.0.88
2016-07-12T18:50:21Z DEBUG Found reverse name: ipa01-aws.rsinc.local
2016-07-12T18:50:21Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmprj5lWPipa' '-N' '-f' '/tmp/tmprj5lWPipa/pwdfile.txt'
2016-07-12T18:50:21Z DEBUG Process finished, return code=0
2016-07-12T18:50:21Z DEBUG stdout=
2016-07-12T18:50:21Z DEBUG stderr=
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/pk12util' '-d' '/tmp/tmprj5lWPipa' '-i' '/tmp/tmp34bUDTipa/realm_info/dscert.p12' '-k' '/tmp/tmprj5lWPipa/pwdfile.txt' '-v' '-w' '/dev/stdin'
2016-07-12T18:50:21Z DEBUG Process finished, return code=0
2016-07-12T18:50:21Z DEBUG stdout=pk12util: PKCS12 IMPORT SUCCESSFUL

2016-07-12T18:50:21Z DEBUG stderr=
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmprj5lWPipa' '-L'
2016-07-12T18:50:21Z DEBUG Process finished, return code=0
2016-07-12T18:50:21Z DEBUG stdout=
Certificate Nickname                                         Trust Attributes
                                                             SSL,S/MIME,JAR/XPI

Server-Cert                                                  u,u,u
RSINC.LOCAL IPA CA                                           ,,

2016-07-12T18:50:21Z DEBUG stderr=
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmprj5lWPipa' '-A' '-n' 'CA 1' '-t' ',,' '-a'
2016-07-12T18:50:21Z DEBUG Process finished, return code=0
2016-07-12T18:50:21Z DEBUG stdout=
2016-07-12T18:50:21Z DEBUG stderr=
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmprj5lWPipa' '-O' '-n' 'Server-Cert'
2016-07-12T18:50:21Z DEBUG Process finished, return code=0
2016-07-12T18:50:21Z DEBUG stdout="RSINC.LOCAL IPA CA" [CN=Certificate Authority,O=RSINC.LOCAL]

  "Server-Cert" [CN=ipa03-aws.rsinc.local,O=RSINC.LOCAL]


2016-07-12T18:50:21Z DEBUG stderr=
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmprj5lWPipa' '-M' '-n' 'RSINC.LOCAL IPA CA' '-t' 'CT,C,C'
2016-07-12T18:50:21Z DEBUG Process finished, return code=0
2016-07-12T18:50:21Z DEBUG stdout=
2016-07-12T18:50:21Z DEBUG stderr=
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmprj5lWPipa' '-O' '-n' 'Server-Cert'
2016-07-12T18:50:21Z DEBUG Process finished, return code=0
2016-07-12T18:50:21Z DEBUG stdout="RSINC.LOCAL IPA CA" [CN=Certificate Authority,O=RSINC.LOCAL]

  "Server-Cert" [CN=ipa03-aws.rsinc.local,O=RSINC.LOCAL]


2016-07-12T18:50:21Z DEBUG stderr=
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmprj5lWPipa' '-L' '-n' 'RSINC.LOCAL IPA CA' '-a'
2016-07-12T18:50:21Z DEBUG Process finished, return code=0
2016-07-12T18:50:21Z DEBUG stdout=-----BEGIN CERTIFICATE-----
MIIDkTCCAnmgAwIBAgIBATANBgkqhkiG9w0BAQsFADA2MRQwEgYDVQQKDAtSU0lO
Qy5MT0NBTDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE2MDMx
MTE2NDMxNVoXDTM2MDMxMTE2NDMxNVowNjEUMBIGA1UECgwLUlNJTkMuTE9DQUwx
HjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTCCASIwDQYJKoZIhvcNAQEB
BQADggEPADCCAQoCggEBAMeuq3fFabQUU4lMQmLEQmN4ryu3bp6ekaBc/+4txdYg
AYiSUvZOChcS+6l0XWl/d1u5txR5BIKdADCvO9rcIglQbvn1y6scjbmMqzd4xtCE
IN28t1ywPQlWIAGSLw2VDuZ/lmKxmyG00RMxKRvZYuWe/pHZqiza9Rywyt+hjxDK
GjghSMGujqYiGXuDviR79q+g7WFQP+8e3D59NmGa8N9iGHaVOBYiNBJIS9raDWmY
LvpHY5cBUYrhBGsIIia3l+V2a+9RPXceF7dN5b3xVae5BK2r39ohFtzZw6b1StVS
QLeuAexrabVUZEEltzcSUyZo1pZqfsOfyOA5LUWsIsUCAwEAAaOBqTCBpjAfBgNV
HSMEGDAWgBS7H+9FH63CaSCM3WK2HMFJFSqzUjAPBgNVHRMBAf8EBTADAQH/MA4G
A1UdDwEB/wQEAwIBxjAdBgNVHQ4EFgQUux/vRR+twmkgjN1ithzBSRUqs1IwQwYI
KwYBBQUHAQEENzA1MDMGCCsGAQUFBzABhidodHRwOi8vaXBhMDEtYXdzLnJzaW5j
LmxvY2FsOjgwL2NhL29jc3AwDQYJKoZIhvcNAQELBQADggEBAIuAZ1+x3we31MvO
ZRB3fg3F8JVALb8iZ8EMSktNIlW71A6UwlwMwJi/1yGBuTAp6GwgZTKETBJ40hqx
1G7DSXaViXmIf8ERRvM/0LEba+Skokt9N+F+kQeOE340/YEMvUR/uiGaaEurA3dm
WsoJ0z/X401qHLH7XIyTKubI+TK6unVFwO+p6OUb/n+/ZTBPY5CluwsH67qHxAFf
WBsn6fd+2kl10LC6Z/drQ+yPbApn8wo0k1Pvht2w01nFji9z3C6zsk7JG+EJ0l8W
LqXaFqEeRJlG+aPmadqEYDWBE8A05+5euoc8z/zLJXZLWSMs4PpKwcuWlWZ+84gV
N2jzdNA=
-----END CERTIFICATE-----

2016-07-12T18:50:21Z DEBUG stderr=
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmprj5lWPipa' '-L'
2016-07-12T18:50:21Z DEBUG Process finished, return code=0
2016-07-12T18:50:21Z DEBUG stdout=
Certificate Nickname                                         Trust Attributes
                                                             SSL,S/MIME,JAR/XPI

Server-Cert                                                  u,u,u
RSINC.LOCAL IPA CA                                           CT,C,C

2016-07-12T18:50:21Z DEBUG stderr=
2016-07-12T18:50:21Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpX8lR1Xipa' '-N' '-f' '/tmp/tmpX8lR1Xipa/pwdfile.txt'
2016-07-12T18:50:21Z DEBUG Process finished, return code=0
2016-07-12T18:50:21Z DEBUG stdout=
2016-07-12T18:50:21Z DEBUG stderr=
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/pk12util' '-d' '/tmp/tmpX8lR1Xipa' '-i' '/tmp/tmp34bUDTipa/realm_info/httpcert.p12' '-k' '/tmp/tmpX8lR1Xipa/pwdfile.txt' '-v' '-w' '/dev/stdin'
2016-07-12T18:50:22Z DEBUG Process finished, return code=0
2016-07-12T18:50:22Z DEBUG stdout=pk12util: PKCS12 IMPORT SUCCESSFUL

2016-07-12T18:50:22Z DEBUG stderr=
2016-07-12T18:50:22Z DEBUG Starting external process
2016-07-12T18:50:22Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpX8lR1Xipa' '-L'
2016-07-12T18:50:22Z DEBUG Process finished, return code=0
2016-07-12T18:50:22Z DEBUG stdout=
Certificate Nickname                                         Trust Attributes
                                                             SSL,S/MIME,JAR/XPI

Server-Cert                                                  u,u,u
RSINC.LOCAL IPA CA                                           ,,

2016-07-12T18:50:22Z DEBUG stderr=
2016-07-12T18:50:22Z DEBUG Starting external process
2016-07-12T18:50:22Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpX8lR1Xipa' '-A' '-n' 'CA 1' '-t' ',,' '-a'
2016-07-12T18:50:22Z DEBUG Process finished, return code=0
2016-07-12T18:50:22Z DEBUG stdout=
2016-07-12T18:50:22Z DEBUG stderr=
2016-07-12T18:50:22Z DEBUG Starting external process
2016-07-12T18:50:22Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpX8lR1Xipa' '-O' '-n' 'Server-Cert'
2016-07-12T18:50:22Z DEBUG Process finished, return code=0
2016-07-12T18:50:22Z DEBUG stdout="RSINC.LOCAL IPA CA" [CN=Certificate Authority,O=RSINC.LOCAL]

  "Server-Cert" [CN=ipa03-aws.rsinc.local,O=RSINC.LOCAL]


2016-07-12T18:50:22Z DEBUG stderr=
2016-07-12T18:50:22Z DEBUG Starting external process
2016-07-12T18:50:22Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpX8lR1Xipa' '-M' '-n' 'RSINC.LOCAL IPA CA' '-t' 'CT,C,C'
2016-07-12T18:50:22Z DEBUG Process finished, return code=0
2016-07-12T18:50:22Z DEBUG stdout=
2016-07-12T18:50:22Z DEBUG stderr=
2016-07-12T18:50:22Z DEBUG Starting external process
2016-07-12T18:50:22Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpX8lR1Xipa' '-O' '-n' 'Server-Cert'
2016-07-12T18:50:22Z DEBUG Process finished, return code=0
2016-07-12T18:50:22Z DEBUG stdout="RSINC.LOCAL IPA CA" [CN=Certificate Authority,O=RSINC.LOCAL]

  "Server-Cert" [CN=ipa03-aws.rsinc.local,O=RSINC.LOCAL]


2016-07-12T18:50:22Z DEBUG stderr=
2016-07-12T18:50:22Z DEBUG Starting external process
2016-07-12T18:50:22Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpX8lR1Xipa' '-L' '-n' 'RSINC.LOCAL IPA CA' '-a'
2016-07-12T18:50:22Z DEBUG Process finished, return code=0
2016-07-12T18:50:22Z DEBUG stdout=-----BEGIN CERTIFICATE-----
MIIDkTCCAnmgAwIBAgIBATANBgkqhkiG9w0BAQsFADA2MRQwEgYDVQQKDAtSU0lO
Qy5MT0NBTDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE2MDMx
MTE2NDMxNVoXDTM2MDMxMTE2NDMxNVowNjEUMBIGA1UECgwLUlNJTkMuTE9DQUwx
HjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTCCASIwDQYJKoZIhvcNAQEB
BQADggEPADCCAQoCggEBAMeuq3fFabQUU4lMQmLEQmN4ryu3bp6ekaBc/+4txdYg
AYiSUvZOChcS+6l0XWl/d1u5txR5BIKdADCvO9rcIglQbvn1y6scjbmMqzd4xtCE
IN28t1ywPQlWIAGSLw2VDuZ/lmKxmyG00RMxKRvZYuWe/pHZqiza9Rywyt+hjxDK
GjghSMGujqYiGXuDviR79q+g7WFQP+8e3D59NmGa8N9iGHaVOBYiNBJIS9raDWmY
LvpHY5cBUYrhBGsIIia3l+V2a+9RPXceF7dN5b3xVae5BK2r39ohFtzZw6b1StVS
QLeuAexrabVUZEEltzcSUyZo1pZqfsOfyOA5LUWsIsUCAwEAAaOBqTCBpjAfBgNV
HSMEGDAWgBS7H+9FH63CaSCM3WK2HMFJFSqzUjAPBgNVHRMBAf8EBTADAQH/MA4G
A1UdDwEB/wQEAwIBxjAdBgNVHQ4EFgQUux/vRR+twmkgjN1ithzBSRUqs1IwQwYI
KwYBBQUHAQEENzA1MDMGCCsGAQUFBzABhidodHRwOi8vaXBhMDEtYXdzLnJzaW5j
LmxvY2FsOjgwL2NhL29jc3AwDQYJKoZIhvcNAQELBQADggEBAIuAZ1+x3we31MvO
ZRB3fg3F8JVALb8iZ8EMSktNIlW71A6UwlwMwJi/1yGBuTAp6GwgZTKETBJ40hqx
1G7DSXaViXmIf8ERRvM/0LEba+Skokt9N+F+kQeOE340/YEMvUR/uiGaaEurA3dm
WsoJ0z/X401qHLH7XIyTKubI+TK6unVFwO+p6OUb/n+/ZTBPY5CluwsH67qHxAFf
WBsn6fd+2kl10LC6Z/drQ+yPbApn8wo0k1Pvht2w01nFji9z3C6zsk7JG+EJ0l8W
LqXaFqEeRJlG+aPmadqEYDWBE8A05+5euoc8z/zLJXZLWSMs4PpKwcuWlWZ+84gV
N2jzdNA=
-----END CERTIFICATE-----

2016-07-12T18:50:22Z DEBUG stderr=
2016-07-12T18:50:22Z DEBUG Starting external process
2016-07-12T18:50:22Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpX8lR1Xipa' '-L'
2016-07-12T18:50:22Z DEBUG Process finished, return code=0
2016-07-12T18:50:22Z DEBUG stdout=
Certificate Nickname                                         Trust Attributes
                                                             SSL,S/MIME,JAR/XPI

Server-Cert                                                  u,u,u
RSINC.LOCAL IPA CA                                           CT,C,C

2016-07-12T18:50:22Z DEBUG stderr=
2016-07-12T18:50:22Z DEBUG importing all plugin modules in ipalib.plugins...
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.aci
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.automember
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.automount
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.baseldap
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.baseuser
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.batch
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.caacl
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.cert
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.certprofile
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.config
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.delegation
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.dns
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.domainlevel
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.group
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.hbacrule
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.hbacsvc
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.hbacsvcgroup
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.hbactest
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.host
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.hostgroup
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.idrange
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.idviews
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.internal
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.kerberos
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.krbtpolicy
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.migration
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.misc
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.netgroup
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.otpconfig
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.otptoken
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.otptoken_yubikey
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.passwd
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.permission
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.ping
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.pkinit
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.privilege
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.pwpolicy
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.radiusproxy
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.realmdomains
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.role
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.rpcclient
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.selfservice
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.selinuxusermap
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.server
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.service
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.servicedelegation
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.session
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.stageuser
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.sudocmd
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.sudocmdgroup
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.sudorule
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.topology
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.trust
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.user
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.vault
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.virtual
2016-07-12T18:50:22Z DEBUG importing all plugin modules in ipaserver.plugins...
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.plugins.dogtag
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.plugins.join
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.plugins.ldap2
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.plugins.rabase
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.plugins.xmlserver
2016-07-12T18:50:22Z DEBUG importing all plugin modules in ipaserver.install.plugins...
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.adtrust
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.dns
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.update_nis
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.update_referint
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.update_services
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt
2016-07-12T18:50:22Z DEBUG SessionAuthManager.register: name=jsonserver_session_90330320
2016-07-12T18:50:22Z DEBUG SessionAuthManager.register: name=xmlserver_session_90332176
2016-07-12T18:50:22Z DEBUG Mounting ipaserver.rpcserver.jsonserver_kerb() at '/json'
2016-07-12T18:50:22Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:22Z DEBUG Mounting ipaserver.rpcserver.xmlserver_session() at '/session/xml'
2016-07-12T18:50:22Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:22Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:22Z DEBUG Mounting ipaserver.rpcserver.sync_token() at '/session/sync_token'
2016-07-12T18:50:22Z DEBUG Mounting ipaserver.rpcserver.xmlserver() at '/xml'
2016-07-12T18:50:22Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:22Z DEBUG Mounting ipaserver.rpcserver.jsonserver_session() at '/session/json'
2016-07-12T18:50:22Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:22Z DEBUG Mounting ipaserver.rpcserver.login_kerberos() at '/session/login_kerberos'
2016-07-12T18:50:22Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:22Z DEBUG Mounting ipaserver.rpcserver.login_password() at '/session/login_password'
2016-07-12T18:50:22Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:22Z DEBUG Mounting ipaserver.rpcserver.change_password() at '/session/change_password'
2016-07-12T18:50:24Z DEBUG Created connection context.ldap2_90329936
2016-07-12T18:50:25Z DEBUG raw: domainlevel_get(version=u'2.156')
2016-07-12T18:50:25Z DEBUG domainlevel_get(version=u'2.156')
2016-07-12T18:50:25Z DEBUG flushing ldaps://ipa01-aws.rsinc.local from SchemaCache
2016-07-12T18:50:25Z DEBUG retrieving schema for SchemaCache url=ldaps://ipa01-aws.rsinc.local conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x21ce7a0>
2016-07-12T18:50:29Z DEBUG Check forward/reverse DNS resolution
2016-07-12T18:50:29Z DEBUG Search DNS server ipa01-aws.rsinc.local (['10.10.0.88', '10.10.0.88', '10.10.0.88']) for ipa01-aws.rsinc.local
2016-07-12T18:50:30Z DEBUG Check reverse address 10.10.0.88 (ipa01-aws.rsinc.local)
2016-07-12T18:50:30Z DEBUG Address 10.10.0.88 resolves to: ipa01-aws.rsinc.local..
2016-07-12T18:50:35Z DEBUG Search DNS server ipa01-aws.rsinc.local (['10.10.0.88', '10.10.0.88', '10.10.0.88']) for ipa03-aws.rsinc.local
2016-07-12T18:50:37Z DEBUG Check reverse address 10.40.0.242 (ipa03-aws.rsinc.local)
2016-07-12T18:50:37Z DEBUG Address 10.40.0.242 resolves to: ipa03-aws.rsinc.local..
2016-07-12T18:50:37Z DEBUG Destroyed connection context.ldap2_90329936
2016-07-12T18:50:37Z DEBUG Starting external process
2016-07-12T18:50:37Z DEBUG args='/sbin/ip' '-family' 'inet' '-oneline' 'address' 'show'
2016-07-12T18:50:37Z DEBUG Process finished, return code=0
2016-07-12T18:50:37Z DEBUG stdout=1: lo    inet 127.0.0.1/8 scope host lo\       valid_lft forever preferred_lft forever
2: eth0    inet 10.40.0.242/24 brd 10.40.0.255 scope global dynamic eth0\       valid_lft 2160sec preferred_lft 2160sec

2016-07-12T18:50:37Z DEBUG stderr=
2016-07-12T18:50:37Z DEBUG Starting external process
2016-07-12T18:50:37Z DEBUG args='/usr/sbin/ipa-replica-conncheck' '--master' 'ipa01-aws.rsinc.local' '--auto-master-check' '--realm' 'RSINC.LOCAL' '--principal' 'admin' '--hostname' 'ipa03-aws.rsinc.local'
2016-07-12T18:51:19Z DEBUG Process finished, return code=0
2016-07-12T18:51:19Z DEBUG group dirsrv exists
2016-07-12T18:51:19Z DEBUG user dirsrv exists
2016-07-12T18:51:25Z DEBUG Created connection context.ldap2_90329936
2016-07-12T18:51:25Z DEBUG flushing ldaps://ipa01-aws.rsinc.local from SchemaCache
2016-07-12T18:51:25Z DEBUG retrieving schema for SchemaCache url=ldaps://ipa01-aws.rsinc.local conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x5750368>
2016-07-12T18:51:25Z DEBUG Starting external process
2016-07-12T18:51:25Z DEBUG args='/bin/systemctl' 'is-enabled' 'chronyd.service'
2016-07-12T18:51:25Z DEBUG Process finished, return code=0
2016-07-12T18:51:25Z DEBUG stdout=enabled

2016-07-12T18:51:25Z DEBUG stderr=
2016-07-12T18:51:25Z DEBUG Starting external process
2016-07-12T18:51:25Z DEBUG args='/bin/systemctl' 'is-active' 'chronyd.service'
2016-07-12T18:51:25Z DEBUG Process finished, return code=0
2016-07-12T18:51:25Z DEBUG stdout=active

2016-07-12T18:51:25Z DEBUG stderr=
2016-07-12T18:51:25Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:25Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:25Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:25Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:25Z DEBUG Starting external process
2016-07-12T18:51:25Z DEBUG args='/bin/systemctl' 'stop' 'chronyd.service'
2016-07-12T18:51:25Z DEBUG Process finished, return code=0
2016-07-12T18:51:25Z DEBUG stdout=
2016-07-12T18:51:25Z DEBUG stderr=
2016-07-12T18:51:25Z DEBUG Starting external process
2016-07-12T18:51:25Z DEBUG args='/bin/systemctl' 'disable' 'chronyd.service'
2016-07-12T18:51:26Z DEBUG Process finished, return code=0
2016-07-12T18:51:26Z DEBUG stdout=
2016-07-12T18:51:26Z DEBUG stderr=Removed symlink /etc/systemd/system/multi-user.target.wants/chronyd.service.

2016-07-12T18:51:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:26Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:51:26Z DEBUG Configuring NTP daemon (ntpd)
2016-07-12T18:51:26Z DEBUG   [1/4]: stopping ntpd
2016-07-12T18:51:26Z DEBUG Starting external process
2016-07-12T18:51:26Z DEBUG args='/bin/systemctl' 'is-active' 'ntpd.service'
2016-07-12T18:51:26Z DEBUG Process finished, return code=3
2016-07-12T18:51:26Z DEBUG stdout=unknown

2016-07-12T18:51:26Z DEBUG stderr=
2016-07-12T18:51:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:26Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:26Z DEBUG Starting external process
2016-07-12T18:51:26Z DEBUG args='/bin/systemctl' 'stop' 'ntpd.service'
2016-07-12T18:51:26Z DEBUG Process finished, return code=0
2016-07-12T18:51:26Z DEBUG stdout=
2016-07-12T18:51:26Z DEBUG stderr=
2016-07-12T18:51:26Z DEBUG   duration: 0 seconds
2016-07-12T18:51:26Z DEBUG   [2/4]: writing configuration
2016-07-12T18:51:26Z DEBUG Backing up system configuration file '/etc/ntp.conf'
2016-07-12T18:51:26Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:51:26Z DEBUG Backing up system configuration file '/etc/sysconfig/ntpd'
2016-07-12T18:51:26Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:51:26Z DEBUG   duration: 0 seconds
2016-07-12T18:51:26Z DEBUG   [3/4]: configuring ntpd to start on boot
2016-07-12T18:51:26Z DEBUG Starting external process
2016-07-12T18:51:26Z DEBUG args='/bin/systemctl' 'is-enabled' 'ntpd.service'
2016-07-12T18:51:26Z DEBUG Process finished, return code=1
2016-07-12T18:51:26Z DEBUG stdout=disabled

2016-07-12T18:51:26Z DEBUG stderr=
2016-07-12T18:51:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:26Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:26Z DEBUG Starting external process
2016-07-12T18:51:26Z DEBUG args='/bin/systemctl' 'enable' 'ntpd.service'
2016-07-12T18:51:26Z DEBUG Process finished, return code=0
2016-07-12T18:51:26Z DEBUG stdout=
2016-07-12T18:51:26Z DEBUG stderr=Created symlink from /etc/systemd/system/multi-user.target.wants/ntpd.service to /usr/lib/systemd/system/ntpd.service.

2016-07-12T18:51:26Z DEBUG   duration: 0 seconds
2016-07-12T18:51:26Z DEBUG   [4/4]: starting ntpd
2016-07-12T18:51:26Z DEBUG Starting external process
2016-07-12T18:51:26Z DEBUG args='/bin/systemctl' 'start' 'ntpd.service'
2016-07-12T18:51:26Z DEBUG Process finished, return code=0
2016-07-12T18:51:26Z DEBUG stdout=
2016-07-12T18:51:26Z DEBUG stderr=
2016-07-12T18:51:26Z DEBUG Starting external process
2016-07-12T18:51:26Z DEBUG args='/bin/systemctl' 'is-active' 'ntpd.service'
2016-07-12T18:51:26Z DEBUG Process finished, return code=0
2016-07-12T18:51:26Z DEBUG stdout=active

2016-07-12T18:51:26Z DEBUG stderr=
2016-07-12T18:51:26Z DEBUG   duration: 0 seconds
2016-07-12T18:51:26Z DEBUG Done configuring NTP daemon (ntpd).
2016-07-12T18:51:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:26Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:51:26Z DEBUG Configuring directory server (dirsrv). Estimated time: 1 minute
2016-07-12T18:51:26Z DEBUG   [1/38]: creating directory server user
2016-07-12T18:51:26Z DEBUG group dirsrv exists
2016-07-12T18:51:26Z DEBUG user dirsrv exists
2016-07-12T18:51:26Z DEBUG   duration: 0 seconds
2016-07-12T18:51:26Z DEBUG   [2/38]: creating directory server instance
2016-07-12T18:51:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:26Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:26Z DEBUG Backing up system configuration file '/etc/sysconfig/dirsrv'
2016-07-12T18:51:26Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:51:26Z DEBUG
dn: dc=rsinc,dc=local
objectClass: top
objectClass: domain
objectClass: pilotObject
dc: rsinc
info: IPA V2.0

2016-07-12T18:51:26Z DEBUG writing inf template
2016-07-12T18:51:26Z DEBUG
[General]
FullMachineName=   ipa03-aws.rsinc.local
SuiteSpotUserID=   dirsrv
SuiteSpotGroup=    dirsrv
ServerRoot=    /usr/lib64/dirsrv
[slapd]
ServerPort=   389
ServerIdentifier=   RSINC-LOCAL
Suffix=   dc=rsinc,dc=local
RootDN=   cn=Directory Manager
InstallLdifFile= /var/lib/dirsrv/boot.ldif
inst_dir=   /var/lib/dirsrv/scripts-RSINC-LOCAL

2016-07-12T18:51:26Z DEBUG calling setup-ds.pl
2016-07-12T18:51:26Z DEBUG Starting external process
2016-07-12T18:51:26Z DEBUG args='/usr/sbin/setup-ds.pl' '--silent' '--logfile' '-' '-f' '/tmp/tmpl25s3I'
2016-07-12T18:51:29Z DEBUG Process finished, return code=0
2016-07-12T18:51:29Z DEBUG stdout=[16/07/12:18:51:29] - [Setup] Info Your new DS instance 'RSINC-LOCAL' was successfully created.
Your new DS instance 'RSINC-LOCAL' was successfully created.
[16/07/12:18:51:29] - [Setup] Success Exiting . . .
Log file is '-'

Exiting . . .
Log file is '-'


2016-07-12T18:51:29Z DEBUG stderr=
2016-07-12T18:51:29Z DEBUG completed creating ds instance
2016-07-12T18:51:29Z DEBUG restarting ds instance
2016-07-12T18:51:29Z DEBUG Starting external process
2016-07-12T18:51:29Z DEBUG args='/bin/systemctl' '--system' 'daemon-reload'
2016-07-12T18:51:29Z DEBUG Process finished, return code=0
2016-07-12T18:51:29Z DEBUG stdout=
2016-07-12T18:51:29Z DEBUG stderr=
2016-07-12T18:51:29Z DEBUG Starting external process
2016-07-12T18:51:29Z DEBUG args='/bin/systemctl' 'restart' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:51:31Z DEBUG Process finished, return code=0
2016-07-12T18:51:31Z DEBUG stdout=
2016-07-12T18:51:31Z DEBUG stderr=
2016-07-12T18:51:31Z DEBUG Starting external process
2016-07-12T18:51:31Z DEBUG args='/bin/systemctl' 'is-active' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:51:31Z DEBUG Process finished, return code=0
2016-07-12T18:51:31Z DEBUG stdout=active

2016-07-12T18:51:31Z DEBUG stderr=
2016-07-12T18:51:31Z DEBUG wait_for_open_ports: localhost [389] timeout 300
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/bin/systemctl' 'is-active' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=active

2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG done restarting ds instance
2016-07-12T18:51:32Z DEBUG   duration: 6 seconds
2016-07-12T18:51:32Z DEBUG   [3/38]: adding default schema
2016-07-12T18:51:32Z DEBUG   duration: 0 seconds
2016-07-12T18:51:32Z DEBUG   [4/38]: enabling memberof plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/memberof-conf.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpaZTwky'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=replace nsslapd-pluginenabled:
	on
add memberofgroupattr:
	memberUser
add memberofgroupattr:
	memberHost
modifying entry "cn=MemberOf Plugin,cn=plugins,cn=config"
modify complete


2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:32Z DEBUG   duration: 0 seconds
2016-07-12T18:51:32Z DEBUG   [5/38]: enabling winsync plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/ipa-winsync-conf.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpDGr86O'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectclass:
	top
	nsSlapdPlugin
	extensibleObject
add cn:
	ipa-winsync
add nsslapd-pluginpath:
	libipa_winsync
add nsslapd-plugininitfunc:
	ipa_winsync_plugin_init
add nsslapd-pluginDescription:
	Allows IPA to work with the DS windows sync feature
add nsslapd-pluginid:
	ipa-winsync
add nsslapd-pluginversion:
	1.0
add nsslapd-pluginvendor:
	Red Hat
add nsslapd-plugintype:
	preoperation
add nsslapd-pluginenabled:
	on
add nsslapd-plugin-depends-on-type:
	database
add ipaWinSyncRealmFilter:
	(objectclass=krbRealmContainer)
add ipaWinSyncRealmAttr:
	cn
add ipaWinSyncNewEntryFilter:
	(cn=ipaConfig)
add ipaWinSyncNewUserOCAttr:
	ipauserobjectclasses
add ipaWinSyncUserFlatten:
	true
add ipaWinsyncHomeDirAttr:
	ipaHomesRootDir
add ipaWinsyncLoginShellAttr:
	ipaDefaultLoginShell
add ipaWinSyncDefaultGroupAttr:
	ipaDefaultPrimaryGroup
add ipaWinSyncDefaultGroupFilter:
	(gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames)
add ipaWinSyncAcctDisable:
	both
add ipaWinSyncForceSync:
	true
add ipaWinSyncUserAttr:
	uidNumber -1
	gidNumber -1
adding new entry "cn=ipa-winsync,cn=plugins,cn=config"
modify complete


2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:32Z DEBUG   duration: 0 seconds
2016-07-12T18:51:32Z DEBUG   [6/38]: configuring replication version plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/version-conf.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpVufx4k'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectclass:
	top
	nsSlapdPlugin
	extensibleObject
add cn:
	IPA Version Replication
add nsslapd-pluginpath:
	libipa_repl_version
add nsslapd-plugininitfunc:
	repl_version_plugin_init
add nsslapd-plugintype:
	preoperation
add nsslapd-pluginenabled:
	off
add nsslapd-pluginid:
	ipa_repl_version
add nsslapd-pluginversion:
	1.0
add nsslapd-pluginvendor:
	Red Hat, Inc.
add nsslapd-plugindescription:
	IPA Replication version plugin
add nsslapd-plugin-depends-on-type:
	database
add nsslapd-plugin-depends-on-named:
	Multimaster Replication Plugin
adding new entry "cn=IPA Version Replication,cn=plugins,cn=config"
modify complete


2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:32Z DEBUG   duration: 0 seconds
2016-07-12T18:51:32Z DEBUG   [7/38]: enabling IPA enrollment plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpvdwlJ_' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmp0DGRqi'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectclass:
	top
	nsSlapdPlugin
	extensibleObject
add cn:
	ipa_enrollment_extop
add nsslapd-pluginpath:
	libipa_enrollment_extop
add nsslapd-plugininitfunc:
	ipaenrollment_init
add nsslapd-plugintype:
	extendedop
add nsslapd-pluginenabled:
	on
add nsslapd-pluginid:
	ipa_enrollment_extop
add nsslapd-pluginversion:
	1.0
add nsslapd-pluginvendor:
	RedHat
add nsslapd-plugindescription:
	Enroll hosts into the IPA domain
add nsslapd-plugin-depends-on-type:
	database
add nsslapd-realmTree:
	dc=rsinc,dc=local
adding new entry "cn=ipa_enrollment_extop,cn=plugins,cn=config"
modify complete


2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:32Z DEBUG   duration: 0 seconds
2016-07-12T18:51:32Z DEBUG   [8/38]: enabling ldapi
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpKj0al8' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpgPe4By'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=replace nsslapd-ldapilisten:
	on
modifying entry "cn=config"
modify complete


2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:32Z DEBUG   duration: 0 seconds
2016-07-12T18:51:32Z DEBUG   [9/38]: configuring uniqueness plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpbK4ppH' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmprrUQX8'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectClass:
	top
	nsSlapdPlugin
	extensibleObject
add cn:
	krbPrincipalName uniqueness
add nsslapd-pluginPath:
	libattr-unique-plugin
add nsslapd-pluginInitfunc:
	NSUniqueAttr_Init
add nsslapd-pluginType:
	preoperation
add nsslapd-pluginEnabled:
	on
add uniqueness-attribute-name:
	krbPrincipalName
add nsslapd-plugin-depends-on-type:
	database
add nsslapd-pluginId:
	NSUniqueAttr
add nsslapd-pluginVersion:
	1.1.0
add nsslapd-pluginVendor:
	Fedora Project
add nsslapd-pluginDescription:
	Enforce unique attribute values
add uniqueness-subtrees:
	dc=rsinc,dc=local
add uniqueness-exclude-subtrees:
	cn=staged users,cn=accounts,cn=provisioning,dc=rsinc,dc=local
add uniqueness-across-all-subtrees:
	on
adding new entry "cn=krbPrincipalName uniqueness,cn=plugins,cn=config"
modify complete

add objectClass:
	top
	nsSlapdPlugin
	extensibleObject
add cn:
	krbCanonicalName uniqueness
add nsslapd-pluginPath:
	libattr-unique-plugin
add nsslapd-pluginInitfunc:
	NSUniqueAttr_Init
add nsslapd-pluginType:
	preoperation
add nsslapd-pluginEnabled:
	on
add uniqueness-attribute-name:
	krbCanonicalName
add nsslapd-plugin-depends-on-type:
	database
add nsslapd-pluginId:
	NSUniqueAttr
add nsslapd-pluginVersion:
	1.1.0
add nsslapd-pluginVendor:
	Fedora Project
add nsslapd-pluginDescription:
	Enforce unique attribute values
add uniqueness-subtrees:
	dc=rsinc,dc=local
add uniqueness-exclude-subtrees:
	cn=staged users,cn=accounts,cn=provisioning,dc=rsinc,dc=local
add uniqueness-across-all-subtrees:
	on
adding new entry "cn=krbCanonicalName uniqueness,cn=plugins,cn=config"
modify complete

add objectClass:
	top
	nsSlapdPlugin
	extensibleObject
add cn:
	netgroup uniqueness
add nsslapd-pluginPath:
	libattr-unique-plugin
add nsslapd-pluginInitfunc:
	NSUniqueAttr_Init
add nsslapd-pluginType:
	preoperation
add nsslapd-pluginEnabled:
	on
add uniqueness-attribute-name:
	cn
add uniqueness-subtrees:
	cn=ng,cn=alt,dc=rsinc,dc=local
add nsslapd-plugin-depends-on-type:
	database
add nsslapd-pluginId:
	NSUniqueAttr
add nsslapd-pluginVersion:
	1.1.0
add nsslapd-pluginVendor:
	Fedora Project
add nsslapd-pluginDescription:
	Enforce unique attribute values
adding new entry "cn=netgroup uniqueness,cn=plugins,cn=config"
modify complete

add objectClass:
	top
	nsSlapdPlugin
	extensibleObject
add cn:
	ipaUniqueID uniqueness
add nsslapd-pluginPath:
	libattr-unique-plugin
add nsslapd-pluginInitfunc:
	NSUniqueAttr_Init
add nsslapd-pluginType:
	preoperation
add nsslapd-pluginEnabled:
	on
add uniqueness-attribute-name:
	ipaUniqueID
add nsslapd-plugin-depends-on-type:
	database
add nsslapd-pluginId:
	NSUniqueAttr
add nsslapd-pluginVersion:
	1.1.0
add nsslapd-pluginVendor:
	Fedora Project
add nsslapd-pluginDescription:
	Enforce unique attribute values
add uniqueness-subtrees:
	dc=rsinc,dc=local
add uniqueness-exclude-subtrees:
	cn=staged users,cn=accounts,cn=provisioning,dc=rsinc,dc=local
add uniqueness-across-all-subtrees:
	on
adding new entry "cn=ipaUniqueID uniqueness,cn=plugins,cn=config"
modify complete

add objectClass:
	top
	nsSlapdPlugin
	extensibleObject
add cn:
	sudorule name uniqueness
add nsslapd-pluginDescription:
	Enforce unique attribute values
add nsslapd-pluginPath:
	libattr-unique-plugin
add nsslapd-pluginInitfunc:
	NSUniqueAttr_Init
add nsslapd-pluginType:
	preoperation
add nsslapd-pluginEnabled:
	on
add uniqueness-attribute-name:
	cn
add uniqueness-subtrees:
	cn=sudorules,cn=sudo,dc=rsinc,dc=local
add nsslapd-plugin-depends-on-type:
	database
add nsslapd-pluginId:
	NSUniqueAttr
add nsslapd-pluginVersion:
	1.1.0
add nsslapd-pluginVendor:
	Fedora Project
adding new entry "cn=sudorule name uniqueness,cn=plugins,cn=config"
modify complete


2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:32Z DEBUG   duration: 0 seconds
2016-07-12T18:51:32Z DEBUG   [10/38]: configuring uuid plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/uuid-conf.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmp5x4unk'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectclass:
	top
	nsSlapdPlugin
	extensibleObject
add cn:
	IPA UUID
add nsslapd-pluginpath:
	libipa_uuid
add nsslapd-plugininitfunc:
	ipauuid_init
add nsslapd-plugintype:
	preoperation
add nsslapd-pluginenabled:
	on
add nsslapd-pluginid:
	ipauuid_version
add nsslapd-pluginversion:
	1.0
add nsslapd-pluginvendor:
	Red Hat, Inc.
add nsslapd-plugindescription:
	IPA UUID plugin
add nsslapd-plugin-depends-on-type:
	database
adding new entry "cn=IPA UUID,cn=plugins,cn=config"
modify complete


2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpgvIJlO' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpcigfIB'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectclass:
	top
	extensibleObject
add cn:
	IPA Unique IDs
add ipaUuidAttr:
	ipaUniqueID
add ipaUuidMagicRegen:
	autogenerate
add ipaUuidFilter:
	(|(objectclass=ipaObject)(objectclass=ipaAssociation))
add ipaUuidScope:
	dc=rsinc,dc=local
add ipaUuidEnforce:
	TRUE
adding new entry "cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config"
modify complete

add objectclass:
	top
	extensibleObject
add cn:
	IPK11 Unique IDs
add ipaUuidAttr:
	ipk11UniqueID
add ipaUuidMagicRegen:
	autogenerate
add ipaUuidFilter:
	(objectclass=ipk11Object)
add ipaUuidScope:
	dc=rsinc,dc=local
add ipaUuidEnforce:
	FALSE
adding new entry "cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config"
modify complete


2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:32Z DEBUG   duration: 0 seconds
2016-07-12T18:51:32Z DEBUG   [11/38]: configuring modrdn plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/modrdn-conf.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpL0SCll'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectclass:
	top
	nsSlapdPlugin
	extensibleObject
add cn:
	IPA MODRDN
add nsslapd-pluginpath:
	libipa_modrdn
add nsslapd-plugininitfunc:
	ipamodrdn_init
add nsslapd-plugintype:
	betxnpostoperation
add nsslapd-pluginenabled:
	on
add nsslapd-pluginid:
	ipamodrdn_version
add nsslapd-pluginversion:
	1.0
add nsslapd-pluginvendor:
	Red Hat, Inc.
add nsslapd-plugindescription:
	IPA MODRDN plugin
add nsslapd-plugin-depends-on-type:
	database
add nsslapd-pluginPrecedence:
	60
adding new entry "cn=IPA MODRDN,cn=plugins,cn=config"
modify complete


2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmp7a9Iy2' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpYqIrA8'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectclass:
	top
	extensibleObject
add cn:
	Kerberos Principal Name
add ipaModRDNsourceAttr:
	uid
add ipaModRDNtargetAttr:
	krbPrincipalName
add ipaModRDNsuffix:
	@RSINC.LOCAL
add ipaModRDNfilter:
	(&(objectclass=posixaccount)(objectclass=krbPrincipalAux))
add ipaModRDNscope:
	dc=rsinc,dc=local
adding new entry "cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config"
modify complete


2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:32Z DEBUG   duration: 0 seconds
2016-07-12T18:51:32Z DEBUG   [12/38]: configuring DNS plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/ipa-dns-conf.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpYTbMOB'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectclass:
	top
	nsslapdPlugin
	extensibleObject
add cn:
	IPA DNS
add nsslapd-plugindescription:
	IPA DNS support plugin
add nsslapd-pluginenabled:
	on
add nsslapd-pluginid:
	ipa_dns
add nsslapd-plugininitfunc:
	ipadns_init
add nsslapd-pluginpath:
	libipa_dns.so
add nsslapd-plugintype:
	preoperation
add nsslapd-pluginvendor:
	Red Hat, Inc.
add nsslapd-pluginversion:
	1.0
add nsslapd-plugin-depends-on-type:
	database
adding new entry "cn=IPA DNS,cn=plugins,cn=config"
modify complete


2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:32Z DEBUG   duration: 0 seconds
2016-07-12T18:51:32Z DEBUG   [13/38]: enabling entryUSN plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/entryusn.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpQNVKqh'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=replace nsslapd-entryusn-global:
	on
modifying entry "cn=config"
modify complete

replace nsslapd-entryusn-import-initval:
	next
modifying entry "cn=config"
modify complete

replace nsslapd-pluginenabled:
	on
modifying entry "cn=USN,cn=plugins,cn=config"
modify complete


2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:32Z DEBUG   duration: 0 seconds
2016-07-12T18:51:32Z DEBUG   [14/38]: configuring lockout plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/lockout-conf.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpuM9MKr'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectclass:
	top
	nsSlapdPlugin
	extensibleObject
add cn:
	IPA Lockout
add nsslapd-pluginpath:
	libipa_lockout
add nsslapd-plugininitfunc:
	ipalockout_init
add nsslapd-plugintype:
	object
add nsslapd-pluginenabled:
	on
add nsslapd-pluginid:
	ipalockout_version
add nsslapd-pluginversion:
	1.0
add nsslapd-pluginvendor:
	Red Hat, Inc.
add nsslapd-plugindescription:
	IPA Lockout plugin
add nsslapd-plugin-depends-on-type:
	database
adding new entry "cn=IPA Lockout,cn=plugins,cn=config"
modify complete


2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:32Z DEBUG   duration: 0 seconds
2016-07-12T18:51:32Z DEBUG   [15/38]: creating indices
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/indices.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmptbeIHR'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectClass:
	top
	nsIndex
add cn:
	krbPrincipalName
add nsSystemIndex:
	false
add nsIndexType:
	eq
	sub
adding new entry "cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add objectClass:
	top
	nsIndex
add cn:
	ou
add nsSystemIndex:
	false
add nsIndexType:
	eq
	sub
adding new entry "cn=ou,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add objectClass:
	top
	nsIndex
add cn:
	carLicense
add nsSystemIndex:
	false
add nsIndexType:
	eq
	sub
adding new entry "cn=carLicense,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add objectClass:
	top
	nsIndex
add cn:
	title
add nsSystemIndex:
	false
add nsIndexType:
	eq
	sub
adding new entry "cn=title,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add objectClass:
	top
	nsIndex
add cn:
	manager
add nsSystemIndex:
	false
add nsIndexType:
	eq
	pres
	sub
adding new entry "cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add objectClass:
	top
	nsIndex
add cn:
	secretary
add nsSystemIndex:
	false
add nsIndexType:
	eq
	pres
	sub
adding new entry "cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add objectClass:
	top
	nsIndex
add cn:
	displayname
add nsSystemIndex:
	false
add nsIndexType:
	eq
	sub
adding new entry "cn=displayname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add nsIndexType:
	sub
modifying entry "cn=uid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add objectClass:
	top
	nsIndex
add cn:
	uidnumber
add nsSystemIndex:
	false
add nsIndexType:
	eq
add nsMatchingRule:
	integerOrderingMatch
adding new entry "cn=uidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add objectClass:
	top
	nsIndex
add cn:
	gidnumber
add nsSystemIndex:
	false
add nsIndexType:
	eq
add nsMatchingRule:
	integerOrderingMatch
adding new entry "cn=gidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

replace nsIndexType:
	eq
	pres
modifying entry "cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

replace nsIndexType:
	eq
	pres
modifying entry "cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add ObjectClass:
	top
	nsIndex
add cn:
	fqdn
add nsSystemIndex:
	false
add nsIndexType:
	eq
	pres
adding new entry "cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add ObjectClass:
	top
	nsIndex
add cn:
	macAddress
add nsSystemIndex:
	false
add nsIndexType:
	eq
	pres
adding new entry "cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add cn:
	memberHost
add ObjectClass:
	top
	nsIndex
add nsSystemIndex:
	false
add nsIndexType:
	eq
	pres
	sub
adding new entry "cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add cn:
	memberUser
add ObjectClass:
	top
	nsIndex
add nsSystemIndex:
	false
add nsIndexType:
	eq
	pres
	sub
adding new entry "cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add cn:
	sourcehost
add ObjectClass:
	top
	nsIndex
add nsSystemIndex:
	false
add nsIndexType:
	eq
	pres
	sub
adding new entry "cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add cn:
	memberservice
add ObjectClass:
	top
	nsIndex
add nsSystemIndex:
	false
add nsIndexType:
	eq
	pres
	sub
adding new entry "cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add cn:
	managedby
add ObjectClass:
	top
	nsIndex
add nsSystemIndex:
	false
add nsIndexType:
	eq
	pres
	sub
adding new entry "cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add cn:
	memberallowcmd
add ObjectClass:
	top
	nsIndex
add nsSystemIndex:
	false
add nsIndexType:
	eq
	pres
	sub
adding new entry "cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add cn:
	memberdenycmd
add ObjectClass:
	top
	nsIndex
add nsSystemIndex:
	false
add nsIndexType:
	eq
	pres
	sub
adding new entry "cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add cn:
	ipasudorunas
add ObjectClass:
	top
	nsIndex
add nsSystemIndex:
	false
add nsIndexType:
	eq
	pres
	sub
adding new entry "cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add cn:
	ipasudorunasgroup
add ObjectClass:
	top
	nsIndex
add nsSystemIndex:
	false
add nsIndexType:
	eq
	pres
	sub
adding new entry "cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add cn:
	automountkey
add ObjectClass:
	top
	nsIndex
add nsSystemIndex:
	false
add nsIndexType:
	eq
adding new entry "cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add cn:
	ipakrbprincipalalias
add ObjectClass:
	top
	nsIndex
add nsSystemIndex:
	false
add nsIndexType:
	eq
adding new entry "cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add cn:
	ipauniqueid
add ObjectClass:
	top
	nsIndex
add nsSystemIndex:
	false
add nsIndexType:
	eq
adding new entry "cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add cn:
	ipaMemberCa
add ObjectClass:
	top
	nsIndex
add nsSystemIndex:
	false
add nsIndexType:
	eq
	pres
	sub
adding new entry "cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add cn:
	ipaMemberCertProfile
add ObjectClass:
	top
	nsIndex
add nsSystemIndex:
	false
add nsIndexType:
	eq
	pres
	sub
adding new entry "cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add cn:
	userCertificate
add ObjectClass:
	top
	nsIndex
add nsSystemIndex:
	false
add nsIndexType:
	eq
	pres
adding new entry "cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete


2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:32Z DEBUG   duration: 0 seconds
2016-07-12T18:51:32Z DEBUG   [16/38]: enabling referential integrity plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/referint-conf.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpQ3LiVG'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=replace nsslapd-pluginenabled:
	on
modifying entry "cn=referential integrity postoperation,cn=plugins,cn=config"
modify complete


2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:32Z DEBUG   duration: 0 seconds
2016-07-12T18:51:32Z DEBUG   [17/38]: configuring ssl for ds instance
2016-07-12T18:51:32Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-N' '-f' '/etc/dirsrv/slapd-RSINC-LOCAL//pwdfile.txt'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=
2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/pk12util' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-i' '/tmp/tmp34bUDTipa/realm_info/dscert.p12' '-k' '/etc/dirsrv/slapd-RSINC-LOCAL//pwdfile.txt' '-v' '-w' '/dev/stdin'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=pk12util: PKCS12 IMPORT SUCCESSFUL

2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-L'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=
Certificate Nickname                                         Trust Attributes
                                                             SSL,S/MIME,JAR/XPI

Server-Cert                                                  u,u,u
RSINC.LOCAL IPA CA                                           ,,

2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-A' '-n' 'CA 1' '-t' ',,' '-a'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=
2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-O' '-n' 'Server-Cert'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout="RSINC.LOCAL IPA CA" [CN=Certificate Authority,O=RSINC.LOCAL]

  "Server-Cert" [CN=ipa03-aws.rsinc.local,O=RSINC.LOCAL]


2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-M' '-n' 'RSINC.LOCAL IPA CA' '-t' 'CT,C,C'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=
2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-O' '-n' 'Server-Cert'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout="RSINC.LOCAL IPA CA" [CN=Certificate Authority,O=RSINC.LOCAL]

  "Server-Cert" [CN=ipa03-aws.rsinc.local,O=RSINC.LOCAL]


2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-L' '-n' 'RSINC.LOCAL IPA CA' '-a'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=-----BEGIN CERTIFICATE-----
MIIDkTCCAnmgAwIBAgIBATANBgkqhkiG9w0BAQsFADA2MRQwEgYDVQQKDAtSU0lO
Qy5MT0NBTDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE2MDMx
MTE2NDMxNVoXDTM2MDMxMTE2NDMxNVowNjEUMBIGA1UECgwLUlNJTkMuTE9DQUwx
HjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTCCASIwDQYJKoZIhvcNAQEB
BQADggEPADCCAQoCggEBAMeuq3fFabQUU4lMQmLEQmN4ryu3bp6ekaBc/+4txdYg
AYiSUvZOChcS+6l0XWl/d1u5txR5BIKdADCvO9rcIglQbvn1y6scjbmMqzd4xtCE
IN28t1ywPQlWIAGSLw2VDuZ/lmKxmyG00RMxKRvZYuWe/pHZqiza9Rywyt+hjxDK
GjghSMGujqYiGXuDviR79q+g7WFQP+8e3D59NmGa8N9iGHaVOBYiNBJIS9raDWmY
LvpHY5cBUYrhBGsIIia3l+V2a+9RPXceF7dN5b3xVae5BK2r39ohFtzZw6b1StVS
QLeuAexrabVUZEEltzcSUyZo1pZqfsOfyOA5LUWsIsUCAwEAAaOBqTCBpjAfBgNV
HSMEGDAWgBS7H+9FH63CaSCM3WK2HMFJFSqzUjAPBgNVHRMBAf8EBTADAQH/MA4G
A1UdDwEB/wQEAwIBxjAdBgNVHQ4EFgQUux/vRR+twmkgjN1ithzBSRUqs1IwQwYI
KwYBBQUHAQEENzA1MDMGCCsGAQUFBzABhidodHRwOi8vaXBhMDEtYXdzLnJzaW5j
LmxvY2FsOjgwL2NhL29jc3AwDQYJKoZIhvcNAQELBQADggEBAIuAZ1+x3we31MvO
ZRB3fg3F8JVALb8iZ8EMSktNIlW71A6UwlwMwJi/1yGBuTAp6GwgZTKETBJ40hqx
1G7DSXaViXmIf8ERRvM/0LEba+Skokt9N+F+kQeOE340/YEMvUR/uiGaaEurA3dm
WsoJ0z/X401qHLH7XIyTKubI+TK6unVFwO+p6OUb/n+/ZTBPY5CluwsH67qHxAFf
WBsn6fd+2kl10LC6Z/drQ+yPbApn8wo0k1Pvht2w01nFji9z3C6zsk7JG+EJ0l8W
LqXaFqEeRJlG+aPmadqEYDWBE8A05+5euoc8z/zLJXZLWSMs4PpKwcuWlWZ+84gV
N2jzdNA=
-----END CERTIFICATE-----

2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-L'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=
Certificate Nickname                                         Trust Attributes
                                                             SSL,S/MIME,JAR/XPI

Server-Cert                                                  u,u,u
RSINC.LOCAL IPA CA                                           CT,C,C

2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-L' '-n' 'Server-Cert' '-a'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=-----BEGIN CERTIFICATE-----
MIIEEzCCAvugAwIBAgIBOzANBgkqhkiG9w0BAQsFADA2MRQwEgYDVQQKDAtSU0lO
Qy5MT0NBTDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE2MDcx
MjE4NDczMloXDTE4MDcxMzE4NDczMlowNjEUMBIGA1UECgwLUlNJTkMuTE9DQUwx
HjAcBgNVBAMMFWlwYTAzLWF3cy5yc2luYy5sb2NhbDCCASIwDQYJKoZIhvcNAQEB
BQADggEPADCCAQoCggEBAL71KZYz8sy6erF5VJH0HrZuzikcrEl/4y8MdqzV8NQ2
yRZDlDzLqcj5hs+RafbKFFQyksP1eO5YkeTllATMetFD8vqqFVIpunlr/u8dbTlM
/vlKOZJ0wvlPjc5QeuGtFVZ/z5vqQKKtFHrFziglx8yMAH1C6R4afFhyMqnQigzT
WHWdc3BLQy2xVyadt0oode1PnWu2diwwV3wEbtja4TA9e8lPKdMWHKIpd2l9+iso
iXP+IvuTLJkMwXKEFjUEgNFetPEbOf+EzXtd6iU7BGKxDplxyvkOf3sG5psR1LJa
Hd3Cp1DHf06XceqvzQbIbVPoL0qk560tz0rch30/Ek8CAwEAAaOCASowggEmMB8G
A1UdIwQYMBaAFLsf70UfrcJpIIzdYrYcwUkVKrNSMD0GCCsGAQUFBwEBBDEwLzAt
BggrBgEFBQcwAYYhaHR0cDovL2lwYS1jYS5yc2luYy5sb2NhbC9jYS9vY3NwMA4G
A1UdDwEB/wQEAwIE8DAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwdgYD
VR0fBG8wbTBroDOgMYYvaHR0cDovL2lwYS1jYS5yc2luYy5sb2NhbC9pcGEvY3Js
L01hc3RlckNSTC5iaW6iNKQyMDAxDjAMBgNVBAoMBWlwYWNhMR4wHAYDVQQDDBVD
ZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHQYDVR0OBBYEFLkqG3ftJkzasSZs+3Xrbu/0
967tMA0GCSqGSIb3DQEBCwUAA4IBAQC6C+6HRuRVotLiS6A1dV/5UQmVohfcIg6P
bI7KSpDSLvcVJvA0rxr2QGfUvpgqa4I62mfxe7tefqs+QLwGLUpdG4OYGmOkiDzi
PUuj7BFI9qRVqGrfH+pcsorY5Zz7Z2JjY3v0TSiPImUIw/s4R6izHT7iUCOhVBPf
ZOeGRKbCihWygPeoz/0m0+P3AIT3U6MV/819Y3woLvyJC/OImkZZVI2HcfU/07Yh
TsHUZsavZX4xfwk6pdKYwg4yw5KGUCWL/WR1QPdEr/QDQeo75jQmaS3fIBxQpCva
2YPxLYfcIdP30GCl9dEg4SE3b19L+6Nuv0rbMai4WtPNr6U/jjWM
-----END CERTIFICATE-----

2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-L' '-n' 'Server-Cert' '-a'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=-----BEGIN CERTIFICATE-----
MIIEEzCCAvugAwIBAgIBOzANBgkqhkiG9w0BAQsFADA2MRQwEgYDVQQKDAtSU0lO
Qy5MT0NBTDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE2MDcx
MjE4NDczMloXDTE4MDcxMzE4NDczMlowNjEUMBIGA1UECgwLUlNJTkMuTE9DQUwx
HjAcBgNVBAMMFWlwYTAzLWF3cy5yc2luYy5sb2NhbDCCASIwDQYJKoZIhvcNAQEB
BQADggEPADCCAQoCggEBAL71KZYz8sy6erF5VJH0HrZuzikcrEl/4y8MdqzV8NQ2
yRZDlDzLqcj5hs+RafbKFFQyksP1eO5YkeTllATMetFD8vqqFVIpunlr/u8dbTlM
/vlKOZJ0wvlPjc5QeuGtFVZ/z5vqQKKtFHrFziglx8yMAH1C6R4afFhyMqnQigzT
WHWdc3BLQy2xVyadt0oode1PnWu2diwwV3wEbtja4TA9e8lPKdMWHKIpd2l9+iso
iXP+IvuTLJkMwXKEFjUEgNFetPEbOf+EzXtd6iU7BGKxDplxyvkOf3sG5psR1LJa
Hd3Cp1DHf06XceqvzQbIbVPoL0qk560tz0rch30/Ek8CAwEAAaOCASowggEmMB8G
A1UdIwQYMBaAFLsf70UfrcJpIIzdYrYcwUkVKrNSMD0GCCsGAQUFBwEBBDEwLzAt
BggrBgEFBQcwAYYhaHR0cDovL2lwYS1jYS5yc2luYy5sb2NhbC9jYS9vY3NwMA4G
A1UdDwEB/wQEAwIE8DAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwdgYD
VR0fBG8wbTBroDOgMYYvaHR0cDovL2lwYS1jYS5yc2luYy5sb2NhbC9pcGEvY3Js
L01hc3RlckNSTC5iaW6iNKQyMDAxDjAMBgNVBAoMBWlwYWNhMR4wHAYDVQQDDBVD
ZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHQYDVR0OBBYEFLkqG3ftJkzasSZs+3Xrbu/0
967tMA0GCSqGSIb3DQEBCwUAA4IBAQC6C+6HRuRVotLiS6A1dV/5UQmVohfcIg6P
bI7KSpDSLvcVJvA0rxr2QGfUvpgqa4I62mfxe7tefqs+QLwGLUpdG4OYGmOkiDzi
PUuj7BFI9qRVqGrfH+pcsorY5Zz7Z2JjY3v0TSiPImUIw/s4R6izHT7iUCOhVBPf
ZOeGRKbCihWygPeoz/0m0+P3AIT3U6MV/819Y3woLvyJC/OImkZZVI2HcfU/07Yh
TsHUZsavZX4xfwk6pdKYwg4yw5KGUCWL/WR1QPdEr/QDQeo75jQmaS3fIBxQpCva
2YPxLYfcIdP30GCl9dEg4SE3b19L+6Nuv0rbMai4WtPNr6U/jjWM
-----END CERTIFICATE-----

2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:33Z DEBUG flushing ldap://ipa03-aws.rsinc.local:389 from SchemaCache
2016-07-12T18:51:33Z DEBUG retrieving schema for SchemaCache url=ldap://ipa03-aws.rsinc.local:389 conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x7aad638>
2016-07-12T18:51:33Z DEBUG   duration: 0 seconds
2016-07-12T18:51:33Z DEBUG   [18/38]: configuring certmap.conf
2016-07-12T18:51:33Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state'
2016-07-12T18:51:33Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state'
2016-07-12T18:51:33Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state'
2016-07-12T18:51:33Z DEBUG   duration: 0 seconds
2016-07-12T18:51:33Z DEBUG   [19/38]: configure autobind for root
2016-07-12T18:51:33Z DEBUG Starting external process
2016-07-12T18:51:33Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/root-autobind.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmp6rzPZX'
2016-07-12T18:51:33Z DEBUG Process finished, return code=0
2016-07-12T18:51:33Z DEBUG stdout=add objectClass:
	extensibleObject
	top
add cn:
	root-autobind
add uidNumber:
	0
add gidNumber:
	0
adding new entry "cn=root-autobind,cn=config"
modify complete

replace nsslapd-ldapiautobind:
	on
modifying entry "cn=config"
modify complete

replace nsslapd-ldapimaptoentries:
	on
modifying entry "cn=config"
modify complete


2016-07-12T18:51:33Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:33Z DEBUG   duration: 0 seconds
2016-07-12T18:51:33Z DEBUG   [20/38]: configure new location for managed entries
2016-07-12T18:51:33Z DEBUG Starting external process
2016-07-12T18:51:33Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpcTTK6a' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpA3Dzpt'
2016-07-12T18:51:33Z DEBUG Process finished, return code=0
2016-07-12T18:51:33Z DEBUG stdout=add nsslapd-pluginConfigArea:
	cn=Definitions,cn=Managed Entries,cn=etc,dc=rsinc,dc=local
modifying entry "cn=Managed Entries,cn=plugins,cn=config"
modify complete


2016-07-12T18:51:33Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:33Z DEBUG   duration: 0 seconds
2016-07-12T18:51:33Z DEBUG   [21/38]: configure dirsrv ccache
2016-07-12T18:51:33Z DEBUG Backing up system configuration file '/etc/sysconfig/dirsrv'
2016-07-12T18:51:33Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:51:33Z DEBUG Starting external process
2016-07-12T18:51:33Z DEBUG args='/usr/sbin/selinuxenabled'
2016-07-12T18:51:33Z DEBUG Process finished, return code=0
2016-07-12T18:51:33Z DEBUG stdout=
2016-07-12T18:51:33Z DEBUG stderr=
2016-07-12T18:51:33Z DEBUG Starting external process
2016-07-12T18:51:33Z DEBUG args='/sbin/restorecon' '/etc/sysconfig/dirsrv'
2016-07-12T18:51:33Z DEBUG Process finished, return code=0
2016-07-12T18:51:33Z DEBUG stdout=
2016-07-12T18:51:33Z DEBUG stderr=
2016-07-12T18:51:33Z DEBUG   duration: 0 seconds
2016-07-12T18:51:33Z DEBUG   [22/38]: enable SASL mapping fallback
2016-07-12T18:51:33Z DEBUG Starting external process
2016-07-12T18:51:33Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpiDf5XR' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpU_gcYB'
2016-07-12T18:51:33Z DEBUG Process finished, return code=0
2016-07-12T18:51:33Z DEBUG stdout=replace nsslapd-sasl-mapping-fallback:
	on
modifying entry "cn=config"
modify complete


2016-07-12T18:51:33Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:33Z DEBUG   duration: 0 seconds
2016-07-12T18:51:33Z DEBUG   [23/38]: restarting directory server
2016-07-12T18:51:33Z DEBUG Starting external process
2016-07-12T18:51:33Z DEBUG args='/bin/systemctl' '--system' 'daemon-reload'
2016-07-12T18:51:33Z DEBUG Process finished, return code=0
2016-07-12T18:51:33Z DEBUG stdout=
2016-07-12T18:51:33Z DEBUG stderr=
2016-07-12T18:51:33Z DEBUG Starting external process
2016-07-12T18:51:33Z DEBUG args='/bin/systemctl' 'restart' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:51:34Z DEBUG Process finished, return code=0
2016-07-12T18:51:34Z DEBUG stdout=
2016-07-12T18:51:34Z DEBUG stderr=
2016-07-12T18:51:34Z DEBUG Starting external process
2016-07-12T18:51:34Z DEBUG args='/bin/systemctl' 'is-active' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:51:34Z DEBUG Process finished, return code=0
2016-07-12T18:51:34Z DEBUG stdout=active

2016-07-12T18:51:34Z DEBUG stderr=
2016-07-12T18:51:34Z DEBUG wait_for_open_ports: localhost [389] timeout 300
2016-07-12T18:51:35Z DEBUG Starting external process
2016-07-12T18:51:35Z DEBUG args='/bin/systemctl' 'is-active' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:51:35Z DEBUG Process finished, return code=0
2016-07-12T18:51:35Z DEBUG stdout=active

2016-07-12T18:51:35Z DEBUG stderr=
2016-07-12T18:51:35Z DEBUG   duration: 2 seconds
2016-07-12T18:51:35Z DEBUG   [24/38]: setting up initial replication
2016-07-12T18:51:35Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-RSINC-LOCAL.socket from SchemaCache
2016-07-12T18:51:35Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-RSINC-LOCAL.socket conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x7a96680>
2016-07-12T18:51:35Z DEBUG Starting external process
2016-07-12T18:51:35Z DEBUG args='/bin/systemctl' '--system' 'daemon-reload'
2016-07-12T18:51:35Z DEBUG Process finished, return code=0
2016-07-12T18:51:35Z DEBUG stdout=
2016-07-12T18:51:35Z DEBUG stderr=
2016-07-12T18:51:35Z DEBUG Starting external process
2016-07-12T18:51:35Z DEBUG args='/bin/systemctl' 'restart' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:51:36Z DEBUG Process finished, return code=0
2016-07-12T18:51:36Z DEBUG stdout=
2016-07-12T18:51:36Z DEBUG stderr=
2016-07-12T18:51:36Z DEBUG Starting external process
2016-07-12T18:51:36Z DEBUG args='/bin/systemctl' 'is-active' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:51:36Z DEBUG Process finished, return code=0
2016-07-12T18:51:36Z DEBUG stdout=active

2016-07-12T18:51:36Z DEBUG stderr=
2016-07-12T18:51:36Z DEBUG wait_for_open_ports: localhost [389] timeout 300
2016-07-12T18:51:38Z DEBUG Fetching nsDS5ReplicaId from master [attempt 1/5]
2016-07-12T18:51:38Z DEBUG flushing ldap://ipa01-aws.rsinc.local:389 from SchemaCache
2016-07-12T18:51:38Z DEBUG retrieving schema for SchemaCache url=ldap://ipa01-aws.rsinc.local:389 conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x81dd758>
2016-07-12T18:51:39Z DEBUG Successfully updated nsDS5ReplicaId.
2016-07-12T18:51:39Z DEBUG flushing ldaps://ipa03-aws.rsinc.local:636 from SchemaCache
2016-07-12T18:51:39Z DEBUG retrieving schema for SchemaCache url=ldaps://ipa03-aws.rsinc.local:636 conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x81dd8c0>
2016-07-12T18:51:49Z DEBUG   duration: 14 seconds
2016-07-12T18:51:49Z DEBUG   [25/38]: updating schema
2016-07-12T18:51:49Z DEBUG Starting external process
2016-07-12T18:51:49Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/schema-update.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpWvrmTP'
2016-07-12T18:51:50Z DEBUG Process finished, return code=0
2016-07-12T18:51:50Z DEBUG stdout=add objectClasses:
	( 2.16.840.1.113730.3.2.41 NAME 'nsslapdPlugin' DESC 'Netscape defined objectclass' SUP top MUST ( cn $ nsslapd-pluginPath $ nsslapd-pluginInitFunc $ nsslapd-pluginType $ nsslapd-pluginId $ nsslapd-pluginVersion $ nsslapd-pluginVendor $ nsslapd-pluginDescription $ nsslapd-pluginEnabled ) MAY ( nsslapd-pluginConfigArea $ nsslapd-plugin-depends-on-type ) X-ORIGIN 'Netscape Directory Server' )
	( 2.16.840.1.113730.3.2.317 NAME 'nsSaslMapping' DESC 'Netscape defined objectclass' SUP top MUST ( cn $ nsSaslMapRegexString $ nsSaslMapBaseDNTemplate $ nsSaslMapFilterTemplate ) MAY ( nsSaslMapPriority ) X-ORIGIN 'Netscape Directory Server' )
modifying entry "cn=schema"
modify complete


2016-07-12T18:51:50Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:50Z DEBUG   duration: 0 seconds
2016-07-12T18:51:50Z DEBUG   [26/38]: setting Auto Member configuration
2016-07-12T18:51:50Z DEBUG Starting external process
2016-07-12T18:51:50Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmp1eCPZ_' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpVqf5cB'
2016-07-12T18:51:50Z DEBUG Process finished, return code=0
2016-07-12T18:51:50Z DEBUG stdout=add nsslapd-pluginConfigArea:
	cn=automember,cn=etc,dc=rsinc,dc=local
modifying entry "cn=Auto Membership Plugin,cn=plugins,cn=config"
modify complete


2016-07-12T18:51:50Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:50Z DEBUG   duration: 0 seconds
2016-07-12T18:51:50Z DEBUG   [27/38]: enabling S4U2Proxy delegation
2016-07-12T18:51:50Z DEBUG Starting external process
2016-07-12T18:51:50Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpY17efF' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmp8IK3SH'
2016-07-12T18:51:50Z DEBUG Process finished, return code=0
2016-07-12T18:51:50Z DEBUG stdout=add memberPrincipal:
	HTTP/ipa03-aws.rsinc.local at RSINC.LOCAL
modifying entry "cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=rsinc,dc=local"
modify complete

add memberPrincipal:
	ldap/ipa03-aws.rsinc.local at RSINC.LOCAL
modifying entry "cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=rsinc,dc=local"
modify complete


2016-07-12T18:51:50Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:50Z DEBUG   duration: 0 seconds
2016-07-12T18:51:50Z DEBUG   [28/38]: importing CA certificates from LDAP
2016-07-12T18:51:50Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:51:50Z DEBUG flushing ldap://ipa03-aws.rsinc.local:389 from SchemaCache
2016-07-12T18:51:50Z DEBUG retrieving schema for SchemaCache url=ldap://ipa03-aws.rsinc.local:389 conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x7c80cf8>
2016-07-12T18:51:50Z DEBUG Starting external process
2016-07-12T18:51:50Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-A' '-n' 'RSINC.LOCAL IPA CA' '-t' 'CT,C,C'
2016-07-12T18:51:50Z DEBUG Process finished, return code=0
2016-07-12T18:51:50Z DEBUG stdout=
2016-07-12T18:51:50Z DEBUG stderr=
2016-07-12T18:51:50Z DEBUG   duration: 0 seconds
2016-07-12T18:51:50Z DEBUG   [29/38]: initializing group membership
2016-07-12T18:51:50Z DEBUG   duration: 0 seconds
2016-07-12T18:51:50Z DEBUG   [30/38]: adding master entry
2016-07-12T18:51:50Z DEBUG Starting external process
2016-07-12T18:51:50Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpxaLDRH' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpm2TMAE'
2016-07-12T18:51:50Z DEBUG Process finished, return code=0
2016-07-12T18:51:50Z DEBUG stdout=add objectclass:
	top
	nsContainer
	ipaReplTopoManagedServer
	ipaConfigObject
	ipaSupportedDomainLevelConfig
add cn:
	ipa03-aws.rsinc.local
add ipaReplTopoManagedSuffix:
	dc=rsinc,dc=local
add ipaMinDomainLevel:
	0
add ipaMaxDomainLevel:
	0
adding new entry "cn=ipa03-aws.rsinc.local,cn=masters,cn=ipa,cn=etc,dc=rsinc,dc=local"
modify complete


2016-07-12T18:51:50Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:50Z DEBUG   duration: 0 seconds
2016-07-12T18:51:50Z DEBUG   [31/38]: initializing domain level
2016-07-12T18:51:50Z DEBUG   duration: 0 seconds
2016-07-12T18:51:50Z DEBUG   [32/38]: configuring Posix uid/gid generation
2016-07-12T18:51:50Z DEBUG Starting external process
2016-07-12T18:51:50Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpIYMDRE' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmp2EyXWe'
2016-07-12T18:51:50Z DEBUG Process finished, return code=0
2016-07-12T18:51:50Z DEBUG stdout=add objectclass:
	top
	extensibleObject
add cn:
	Posix IDs
add dnaType:
	uidNumber
	gidNumber
add dnaNextValue:
	1101
add dnaMaxValue:
	1100
add dnaMagicRegen:
	-1
add dnaFilter:
	(|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject))
add dnaScope:
	dc=rsinc,dc=local
add dnaThreshold:
	500
add dnaSharedCfgDN:
	cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=rsinc,dc=local
adding new entry "cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config"
modify complete


2016-07-12T18:51:50Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:50Z DEBUG   duration: 0 seconds
2016-07-12T18:51:50Z DEBUG   [33/38]: adding replication acis
2016-07-12T18:51:50Z DEBUG Starting external process
2016-07-12T18:51:50Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpfjnnUg' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmporl0Uz'
2016-07-12T18:51:50Z DEBUG Process finished, return code=0
2016-07-12T18:51:50Z DEBUG stdout=add aci:
	(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=rsinc,dc=local";)
modifying entry "cn="dc=rsinc,dc=local",cn=mapping tree,cn=config"
modify complete

add aci:
	(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=rsinc,dc=local";)
modifying entry "cn="dc=rsinc,dc=local",cn=mapping tree,cn=config"
modify complete

add aci:
	(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=rsinc,dc=local";)
modifying entry "cn="dc=rsinc,dc=local",cn=mapping tree,cn=config"
modify complete

add aci:
	(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=rsinc,dc=local";)
modifying entry "cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config"
modify complete

add aci:
	(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=rsinc,dc=local";)
modifying entry "cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete

add aci:
	(targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=rsinc,dc=local";)
modifying entry "cn=tasks,cn=config"
modify complete


2016-07-12T18:51:50Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:50Z DEBUG   duration: 0 seconds
2016-07-12T18:51:50Z DEBUG   [34/38]: enabling compatibility plugin
2016-07-12T18:51:50Z DEBUG importing all plugin modules in ipalib.plugins...
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.aci
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.automember
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.automount
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.baseldap
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.baseuser
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.batch
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.caacl
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.cert
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.certprofile
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.config
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.delegation
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.dns
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.domainlevel
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.group
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.hbacrule
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.hbacsvc
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.hbacsvcgroup
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.hbactest
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.host
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.hostgroup
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.idrange
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.idviews
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.internal
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.kerberos
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.krbtpolicy
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.migration
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.misc
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.netgroup
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.otpconfig
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.otptoken
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.otptoken_yubikey
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.passwd
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.permission
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.ping
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.pkinit
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.privilege
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.pwpolicy
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.radiusproxy
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.realmdomains
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.role
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.rpcclient
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.selfservice
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.selinuxusermap
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.server
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.service
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.servicedelegation
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.session
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.stageuser
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.sudocmd
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.sudocmdgroup
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.sudorule
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.topology
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.trust
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.user
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.vault
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.virtual
2016-07-12T18:51:50Z DEBUG importing all plugin modules in ipaserver.plugins...
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.plugins.dogtag
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.plugins.join
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.plugins.ldap2
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.plugins.rabase
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.plugins.xmlserver
2016-07-12T18:51:50Z DEBUG importing all plugin modules in ipaserver.install.plugins...
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.adtrust
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.dns
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.update_nis
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.update_referint
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.update_services
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt
2016-07-12T18:51:50Z DEBUG SessionAuthManager.register: name=jsonserver_session_146012624
2016-07-12T18:51:50Z DEBUG SessionAuthManager.register: name=xmlserver_session_146030864
2016-07-12T18:51:51Z DEBUG Mounting ipaserver.rpcserver.jsonserver_kerb() at '/json'
2016-07-12T18:51:51Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:51:51Z DEBUG Mounting ipaserver.rpcserver.xmlserver_session() at '/session/xml'
2016-07-12T18:51:51Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:51:51Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:51:51Z DEBUG Mounting ipaserver.rpcserver.sync_token() at '/session/sync_token'
2016-07-12T18:51:51Z DEBUG Mounting ipaserver.rpcserver.xmlserver() at '/xml'
2016-07-12T18:51:51Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:51:51Z DEBUG Mounting ipaserver.rpcserver.jsonserver_session() at '/session/json'
2016-07-12T18:51:51Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:51:51Z DEBUG Mounting ipaserver.rpcserver.login_kerberos() at '/session/login_kerberos'
2016-07-12T18:51:51Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:51:51Z DEBUG Mounting ipaserver.rpcserver.login_password() at '/session/login_password'
2016-07-12T18:51:51Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:51:51Z DEBUG Mounting ipaserver.rpcserver.change_password() at '/session/change_password'
2016-07-12T18:51:52Z DEBUG Created connection context.ldap2_146012240
2016-07-12T18:51:52Z DEBUG Destroyed connection context.ldap2_146012240
2016-07-12T18:51:52Z DEBUG Created connection context.ldap2_146012240
2016-07-12T18:51:52Z DEBUG Parsing update file '/usr/share/ipa/schema_compat.uldif'
2016-07-12T18:51:52Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-RSINC-LOCAL.socket from SchemaCache
2016-07-12T18:51:52Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-RSINC-LOCAL.socket conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x264dc68>
2016-07-12T18:51:52Z DEBUG New entry: cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Initial value
2016-07-12T18:51:52Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG nsslapd-pluginid:
2016-07-12T18:51:52Z DEBUG 	schema-compat-plugin
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG 	Schema Compatibility
2016-07-12T18:51:52Z DEBUG nsslapd-pluginbetxn:
2016-07-12T18:51:52Z DEBUG 	on
2016-07-12T18:51:52Z DEBUG objectclass:
2016-07-12T18:51:52Z DEBUG 	top
2016-07-12T18:51:52Z DEBUG 	nsSlapdPlugin
2016-07-12T18:51:52Z DEBUG 	extensibleObject
2016-07-12T18:51:52Z DEBUG nsslapd-plugindescription:
2016-07-12T18:51:52Z DEBUG 	Schema Compatibility Plugin
2016-07-12T18:51:52Z DEBUG nsslapd-pluginenabled:
2016-07-12T18:51:52Z DEBUG 	on
2016-07-12T18:51:52Z DEBUG nsslapd-pluginpath:
2016-07-12T18:51:52Z DEBUG 	/usr/lib64/dirsrv/plugins/schemacompat-plugin.so
2016-07-12T18:51:52Z DEBUG nsslapd-pluginversion:
2016-07-12T18:51:52Z DEBUG 	0.8
2016-07-12T18:51:52Z DEBUG nsslapd-pluginvendor:
2016-07-12T18:51:52Z DEBUG 	redhat.com
2016-07-12T18:51:52Z DEBUG nsslapd-pluginprecedence:
2016-07-12T18:51:52Z DEBUG 	49
2016-07-12T18:51:52Z DEBUG nsslapd-plugintype:
2016-07-12T18:51:52Z DEBUG 	object
2016-07-12T18:51:52Z DEBUG nsslapd-plugininitfunc:
2016-07-12T18:51:52Z DEBUG 	schema_compat_plugin_init
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Final value after applying updates
2016-07-12T18:51:52Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG nsslapd-pluginid:
2016-07-12T18:51:52Z DEBUG 	schema-compat-plugin
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG 	Schema Compatibility
2016-07-12T18:51:52Z DEBUG nsslapd-pluginbetxn:
2016-07-12T18:51:52Z DEBUG 	on
2016-07-12T18:51:52Z DEBUG objectclass:
2016-07-12T18:51:52Z DEBUG 	top
2016-07-12T18:51:52Z DEBUG 	nsSlapdPlugin
2016-07-12T18:51:52Z DEBUG 	extensibleObject
2016-07-12T18:51:52Z DEBUG nsslapd-plugindescription:
2016-07-12T18:51:52Z DEBUG 	Schema Compatibility Plugin
2016-07-12T18:51:52Z DEBUG nsslapd-pluginenabled:
2016-07-12T18:51:52Z DEBUG 	on
2016-07-12T18:51:52Z DEBUG nsslapd-pluginpath:
2016-07-12T18:51:52Z DEBUG 	/usr/lib64/dirsrv/plugins/schemacompat-plugin.so
2016-07-12T18:51:52Z DEBUG nsslapd-pluginversion:
2016-07-12T18:51:52Z DEBUG 	0.8
2016-07-12T18:51:52Z DEBUG nsslapd-pluginvendor:
2016-07-12T18:51:52Z DEBUG 	redhat.com
2016-07-12T18:51:52Z DEBUG nsslapd-pluginprecedence:
2016-07-12T18:51:52Z DEBUG 	49
2016-07-12T18:51:52Z DEBUG nsslapd-plugintype:
2016-07-12T18:51:52Z DEBUG 	object
2016-07-12T18:51:52Z DEBUG nsslapd-plugininitfunc:
2016-07-12T18:51:52Z DEBUG 	schema_compat_plugin_init
2016-07-12T18:51:52Z DEBUG New entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Initial value
2016-07-12T18:51:52Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG schema-compat-entry-attribute:
2016-07-12T18:51:52Z DEBUG 	%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")
2016-07-12T18:51:52Z DEBUG 	cn=%{cn}
2016-07-12T18:51:52Z DEBUG 	objectclass=posixAccount
2016-07-12T18:51:52Z DEBUG 	gidNumber=%{gidNumber}
2016-07-12T18:51:52Z DEBUG 	gecos=%{cn}
2016-07-12T18:51:52Z DEBUG 	ipaanchoruuid=%{ipaanchoruuid}
2016-07-12T18:51:52Z DEBUG 	uidNumber=%{uidNumber}
2016-07-12T18:51:52Z DEBUG 	%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:rsinc.local:%{ipauniqueid}","")
2016-07-12T18:51:52Z DEBUG 	%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")
2016-07-12T18:51:52Z DEBUG 	loginShell=%{loginShell}
2016-07-12T18:51:52Z DEBUG 	homeDirectory=%{homeDirectory}
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG 	users
2016-07-12T18:51:52Z DEBUG objectClass:
2016-07-12T18:51:52Z DEBUG 	top
2016-07-12T18:51:52Z DEBUG 	extensibleObject
2016-07-12T18:51:52Z DEBUG schema-compat-search-filter:
2016-07-12T18:51:52Z DEBUG 	objectclass=posixAccount
2016-07-12T18:51:52Z DEBUG schema-compat-container-rdn:
2016-07-12T18:51:52Z DEBUG 	cn=users
2016-07-12T18:51:52Z DEBUG schema-compat-entry-rdn:
2016-07-12T18:51:52Z DEBUG 	uid=%{uid}
2016-07-12T18:51:52Z DEBUG schema-compat-search-base:
2016-07-12T18:51:52Z DEBUG 	cn=users, cn=accounts, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG schema-compat-container-group:
2016-07-12T18:51:52Z DEBUG 	cn=compat, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Final value after applying updates
2016-07-12T18:51:52Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG schema-compat-entry-attribute:
2016-07-12T18:51:52Z DEBUG 	%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")
2016-07-12T18:51:52Z DEBUG 	cn=%{cn}
2016-07-12T18:51:52Z DEBUG 	objectclass=posixAccount
2016-07-12T18:51:52Z DEBUG 	gidNumber=%{gidNumber}
2016-07-12T18:51:52Z DEBUG 	gecos=%{cn}
2016-07-12T18:51:52Z DEBUG 	ipaanchoruuid=%{ipaanchoruuid}
2016-07-12T18:51:52Z DEBUG 	uidNumber=%{uidNumber}
2016-07-12T18:51:52Z DEBUG 	%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:rsinc.local:%{ipauniqueid}","")
2016-07-12T18:51:52Z DEBUG 	%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")
2016-07-12T18:51:52Z DEBUG 	loginShell=%{loginShell}
2016-07-12T18:51:52Z DEBUG 	homeDirectory=%{homeDirectory}
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG 	users
2016-07-12T18:51:52Z DEBUG objectClass:
2016-07-12T18:51:52Z DEBUG 	top
2016-07-12T18:51:52Z DEBUG 	extensibleObject
2016-07-12T18:51:52Z DEBUG schema-compat-search-filter:
2016-07-12T18:51:52Z DEBUG 	objectclass=posixAccount
2016-07-12T18:51:52Z DEBUG schema-compat-container-rdn:
2016-07-12T18:51:52Z DEBUG 	cn=users
2016-07-12T18:51:52Z DEBUG schema-compat-entry-rdn:
2016-07-12T18:51:52Z DEBUG 	uid=%{uid}
2016-07-12T18:51:52Z DEBUG schema-compat-search-base:
2016-07-12T18:51:52Z DEBUG 	cn=users, cn=accounts, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG schema-compat-container-group:
2016-07-12T18:51:52Z DEBUG 	cn=compat, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG New entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Initial value
2016-07-12T18:51:52Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG schema-compat-entry-attribute:
2016-07-12T18:51:52Z DEBUG 	%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")
2016-07-12T18:51:52Z DEBUG 	ipaanchoruuid=%{ipaanchoruuid}
2016-07-12T18:51:52Z DEBUG 	gidNumber=%{gidNumber}
2016-07-12T18:51:52Z DEBUG 	objectclass=posixGroup
2016-07-12T18:51:52Z DEBUG 	memberUid=%{memberUid}
2016-07-12T18:51:52Z DEBUG 	%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:rsinc.local:%{ipauniqueid}","")
2016-07-12T18:51:52Z DEBUG 	%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")
2016-07-12T18:51:52Z DEBUG 	memberUid=%deref_r("member","uid")
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG 	groups
2016-07-12T18:51:52Z DEBUG objectClass:
2016-07-12T18:51:52Z DEBUG 	top
2016-07-12T18:51:52Z DEBUG 	extensibleObject
2016-07-12T18:51:52Z DEBUG schema-compat-search-filter:
2016-07-12T18:51:52Z DEBUG 	objectclass=posixGroup
2016-07-12T18:51:52Z DEBUG schema-compat-container-rdn:
2016-07-12T18:51:52Z DEBUG 	cn=groups
2016-07-12T18:51:52Z DEBUG schema-compat-entry-rdn:
2016-07-12T18:51:52Z DEBUG 	cn=%{cn}
2016-07-12T18:51:52Z DEBUG schema-compat-search-base:
2016-07-12T18:51:52Z DEBUG 	cn=groups, cn=accounts, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG schema-compat-container-group:
2016-07-12T18:51:52Z DEBUG 	cn=compat, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Final value after applying updates
2016-07-12T18:51:52Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG schema-compat-entry-attribute:
2016-07-12T18:51:52Z DEBUG 	%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")
2016-07-12T18:51:52Z DEBUG 	ipaanchoruuid=%{ipaanchoruuid}
2016-07-12T18:51:52Z DEBUG 	gidNumber=%{gidNumber}
2016-07-12T18:51:52Z DEBUG 	objectclass=posixGroup
2016-07-12T18:51:52Z DEBUG 	memberUid=%{memberUid}
2016-07-12T18:51:52Z DEBUG 	%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:rsinc.local:%{ipauniqueid}","")
2016-07-12T18:51:52Z DEBUG 	%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")
2016-07-12T18:51:52Z DEBUG 	memberUid=%deref_r("member","uid")
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG 	groups
2016-07-12T18:51:52Z DEBUG objectClass:
2016-07-12T18:51:52Z DEBUG 	top
2016-07-12T18:51:52Z DEBUG 	extensibleObject
2016-07-12T18:51:52Z DEBUG schema-compat-search-filter:
2016-07-12T18:51:52Z DEBUG 	objectclass=posixGroup
2016-07-12T18:51:52Z DEBUG schema-compat-container-rdn:
2016-07-12T18:51:52Z DEBUG 	cn=groups
2016-07-12T18:51:52Z DEBUG schema-compat-entry-rdn:
2016-07-12T18:51:52Z DEBUG 	cn=%{cn}
2016-07-12T18:51:52Z DEBUG schema-compat-search-base:
2016-07-12T18:51:52Z DEBUG 	cn=groups, cn=accounts, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG schema-compat-container-group:
2016-07-12T18:51:52Z DEBUG 	cn=compat, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG New entry: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Initial value
2016-07-12T18:51:52Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG add: 'top' to objectClass, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['top']
2016-07-12T18:51:52Z DEBUG add: 'extensibleObject' to objectClass, current value ['top']
2016-07-12T18:51:52Z DEBUG add: updated value ['top', 'extensibleObject']
2016-07-12T18:51:52Z DEBUG add: 'ng' to cn, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['ng']
2016-07-12T18:51:52Z DEBUG add: 'cn=compat, dc=rsinc,dc=local' to schema-compat-container-group, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['cn=compat, dc=rsinc,dc=local']
2016-07-12T18:51:52Z DEBUG add: 'cn=ng' to schema-compat-container-rdn, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['cn=ng']
2016-07-12T18:51:52Z DEBUG add: 'yes' to schema-compat-check-access, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['yes']
2016-07-12T18:51:52Z DEBUG add: 'cn=ng, cn=alt, dc=rsinc,dc=local' to schema-compat-search-base, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['cn=ng, cn=alt, dc=rsinc,dc=local']
2016-07-12T18:51:52Z DEBUG add: '(objectclass=ipaNisNetgroup)' to schema-compat-search-filter, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['(objectclass=ipaNisNetgroup)']
2016-07-12T18:51:52Z DEBUG add: 'cn=%{cn}' to schema-compat-entry-rdn, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['cn=%{cn}']
2016-07-12T18:51:52Z DEBUG add: 'objectclass=nisNetgroup' to schema-compat-entry-attribute, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['objectclass=nisNetgroup']
2016-07-12T18:51:52Z DEBUG add: 'memberNisNetgroup=%deref_r("member","cn")' to schema-compat-entry-attribute, current value ['objectclass=nisNetgroup']
2016-07-12T18:51:52Z DEBUG add: updated value ['objectclass=nisNetgroup', 'memberNisNetgroup=%deref_r("member","cn")']
2016-07-12T18:51:52Z DEBUG add: 'nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-})' to schema-compat-entry-attribute, current value ['memberNisNetgroup=%deref_r("member","cn")', 'objectclass=nisNetgroup']
2016-07-12T18:51:52Z DEBUG add: updated value ['memberNisNetgroup=%deref_r("member","cn")', 'objectclass=nisNetgroup', 'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","-",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","-"),%{nisDomainName:-})']
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Final value after applying updates
2016-07-12T18:51:52Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG schema-compat-entry-attribute:
2016-07-12T18:51:52Z DEBUG 	memberNisNetgroup=%deref_r("member","cn")
2016-07-12T18:51:52Z DEBUG 	objectclass=nisNetgroup
2016-07-12T18:51:52Z DEBUG 	nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-})
2016-07-12T18:51:52Z DEBUG schema-compat-check-access:
2016-07-12T18:51:52Z DEBUG 	yes
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG 	ng
2016-07-12T18:51:52Z DEBUG objectClass:
2016-07-12T18:51:52Z DEBUG 	top
2016-07-12T18:51:52Z DEBUG 	extensibleObject
2016-07-12T18:51:52Z DEBUG schema-compat-search-filter:
2016-07-12T18:51:52Z DEBUG 	(objectclass=ipaNisNetgroup)
2016-07-12T18:51:52Z DEBUG schema-compat-container-rdn:
2016-07-12T18:51:52Z DEBUG 	cn=ng
2016-07-12T18:51:52Z DEBUG schema-compat-entry-rdn:
2016-07-12T18:51:52Z DEBUG 	cn=%{cn}
2016-07-12T18:51:52Z DEBUG schema-compat-search-base:
2016-07-12T18:51:52Z DEBUG 	cn=ng, cn=alt, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG schema-compat-container-group:
2016-07-12T18:51:52Z DEBUG 	cn=compat, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG New entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Initial value
2016-07-12T18:51:52Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG add: 'top' to objectClass, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['top']
2016-07-12T18:51:52Z DEBUG add: 'extensibleObject' to objectClass, current value ['top']
2016-07-12T18:51:52Z DEBUG add: updated value ['top', 'extensibleObject']
2016-07-12T18:51:52Z DEBUG add: 'sudoers' to cn, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoers']
2016-07-12T18:51:52Z DEBUG add: 'ou=SUDOers, dc=rsinc,dc=local' to schema-compat-container-group, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['ou=SUDOers, dc=rsinc,dc=local']
2016-07-12T18:51:52Z DEBUG add: 'cn=sudorules, cn=sudo, dc=rsinc,dc=local' to schema-compat-search-base, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['cn=sudorules, cn=sudo, dc=rsinc,dc=local']
2016-07-12T18:51:52Z DEBUG add: '(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))' to schema-compat-search-filter, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))']
2016-07-12T18:51:52Z DEBUG add: '%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")' to schema-compat-entry-rdn, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")']
2016-07-12T18:51:52Z DEBUG add: 'objectclass=sudoRole' to schema-compat-entry-attribute, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")']
2016-07-12T18:51:52Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")']
2016-07-12T18:51:52Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")']
2016-07-12T18:51:52Z DEBUG add: 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")']
2016-07-12T18:51:52Z DEBUG add: 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")']
2016-07-12T18:51:52Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")']
2016-07-12T18:51:52Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")']
2016-07-12T18:51:52Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")']
2016-07-12T18:51:52Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")']
2016-07-12T18:51:52Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")']
2016-07-12T18:51:52Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoOption=%{ipaSudoOpt}' to schema-compat-entry-attribute, current value ['sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}']
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Final value after applying updates
2016-07-12T18:51:52Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG schema-compat-entry-attribute:
2016-07-12T18:51:52Z DEBUG 	sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")
2016-07-12T18:51:52Z DEBUG 	sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")
2016-07-12T18:51:52Z DEBUG 	sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")")
2016-07-12T18:51:52Z DEBUG 	sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")")
2016-07-12T18:51:52Z DEBUG 	sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")")
2016-07-12T18:51:52Z DEBUG 	sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")
2016-07-12T18:51:52Z DEBUG 	sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")")
2016-07-12T18:51:52Z DEBUG 	sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")
2016-07-12T18:51:52Z DEBUG 	sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")")
2016-07-12T18:51:52Z DEBUG 	sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")")
2016-07-12T18:51:52Z DEBUG 	objectclass=sudoRole
2016-07-12T18:51:52Z DEBUG 	sudoOption=%{ipaSudoOpt}
2016-07-12T18:51:52Z DEBUG 	sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")")
2016-07-12T18:51:52Z DEBUG 	sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")")
2016-07-12T18:51:52Z DEBUG 	sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")
2016-07-12T18:51:52Z DEBUG 	sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")")
2016-07-12T18:51:52Z DEBUG 	sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")
2016-07-12T18:51:52Z DEBUG 	sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")")
2016-07-12T18:51:52Z DEBUG 	sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")
2016-07-12T18:51:52Z DEBUG 	sudoCommand=!%deref("memberDenyCmd","sudoCmd")
2016-07-12T18:51:52Z DEBUG 	sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")
2016-07-12T18:51:52Z DEBUG 	sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")")
2016-07-12T18:51:52Z DEBUG 	sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG 	sudoers
2016-07-12T18:51:52Z DEBUG objectClass:
2016-07-12T18:51:52Z DEBUG 	top
2016-07-12T18:51:52Z DEBUG 	extensibleObject
2016-07-12T18:51:52Z DEBUG schema-compat-search-filter:
2016-07-12T18:51:52Z DEBUG 	(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))
2016-07-12T18:51:52Z DEBUG schema-compat-entry-rdn:
2016-07-12T18:51:52Z DEBUG 	%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")
2016-07-12T18:51:52Z DEBUG schema-compat-search-base:
2016-07-12T18:51:52Z DEBUG 	cn=sudorules, cn=sudo, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG schema-compat-container-group:
2016-07-12T18:51:52Z DEBUG 	ou=SUDOers, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG New entry: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Initial value
2016-07-12T18:51:52Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG schema-compat-entry-attribute:
2016-07-12T18:51:52Z DEBUG 	objectclass=device
2016-07-12T18:51:52Z DEBUG 	cn=%{fqdn}
2016-07-12T18:51:52Z DEBUG 	macAddress=%{macAddress}
2016-07-12T18:51:52Z DEBUG 	objectclass=ieee802Device
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG 	computers
2016-07-12T18:51:52Z DEBUG objectClass:
2016-07-12T18:51:52Z DEBUG 	top
2016-07-12T18:51:52Z DEBUG 	extensibleObject
2016-07-12T18:51:52Z DEBUG schema-compat-search-filter:
2016-07-12T18:51:52Z DEBUG 	(&(macAddress=*)(fqdn=*)(objectClass=ipaHost))
2016-07-12T18:51:52Z DEBUG schema-compat-container-rdn:
2016-07-12T18:51:52Z DEBUG 	cn=computers
2016-07-12T18:51:52Z DEBUG schema-compat-entry-rdn:
2016-07-12T18:51:52Z DEBUG 	cn=%first("%{fqdn}")
2016-07-12T18:51:52Z DEBUG schema-compat-search-base:
2016-07-12T18:51:52Z DEBUG 	cn=computers, cn=accounts, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG schema-compat-container-group:
2016-07-12T18:51:52Z DEBUG 	cn=compat, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Final value after applying updates
2016-07-12T18:51:52Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG schema-compat-entry-attribute:
2016-07-12T18:51:52Z DEBUG 	objectclass=device
2016-07-12T18:51:52Z DEBUG 	cn=%{fqdn}
2016-07-12T18:51:52Z DEBUG 	macAddress=%{macAddress}
2016-07-12T18:51:52Z DEBUG 	objectclass=ieee802Device
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG 	computers
2016-07-12T18:51:52Z DEBUG objectClass:
2016-07-12T18:51:52Z DEBUG 	top
2016-07-12T18:51:52Z DEBUG 	extensibleObject
2016-07-12T18:51:52Z DEBUG schema-compat-search-filter:
2016-07-12T18:51:52Z DEBUG 	(&(macAddress=*)(fqdn=*)(objectClass=ipaHost))
2016-07-12T18:51:52Z DEBUG schema-compat-container-rdn:
2016-07-12T18:51:52Z DEBUG 	cn=computers
2016-07-12T18:51:52Z DEBUG schema-compat-entry-rdn:
2016-07-12T18:51:52Z DEBUG 	cn=%first("%{fqdn}")
2016-07-12T18:51:52Z DEBUG schema-compat-search-base:
2016-07-12T18:51:52Z DEBUG 	cn=computers, cn=accounts, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG schema-compat-container-group:
2016-07-12T18:51:52Z DEBUG 	cn=compat, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG Updating existing entry: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Initial value
2016-07-12T18:51:52Z DEBUG dn: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config
2016-07-12T18:51:52Z DEBUG objectClass:
2016-07-12T18:51:52Z DEBUG 	top
2016-07-12T18:51:52Z DEBUG 	directoryServerFeature
2016-07-12T18:51:52Z DEBUG aci:
2016-07-12T18:51:52Z DEBUG 	(targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";)
2016-07-12T18:51:52Z DEBUG oid:
2016-07-12T18:51:52Z DEBUG 	2.16.840.1.113730.3.4.9
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG 	VLV Request Control
2016-07-12T18:51:52Z DEBUG only: set aci to '(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )', current value ['(targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";)']
2016-07-12T18:51:52Z DEBUG only: updated value ['(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )']
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Final value after applying updates
2016-07-12T18:51:52Z DEBUG dn: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config
2016-07-12T18:51:52Z DEBUG objectClass:
2016-07-12T18:51:52Z DEBUG 	top
2016-07-12T18:51:52Z DEBUG 	directoryServerFeature
2016-07-12T18:51:52Z DEBUG aci:
2016-07-12T18:51:52Z DEBUG 	(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )
2016-07-12T18:51:52Z DEBUG oid:
2016-07-12T18:51:52Z DEBUG 	2.16.840.1.113730.3.4.9
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG 	VLV Request Control
2016-07-12T18:51:52Z DEBUG [(0, u'aci', ['(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )']), (1, u'aci', ['(targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";)'])]
2016-07-12T18:51:52Z DEBUG Updated 1
2016-07-12T18:51:52Z DEBUG Done
2016-07-12T18:51:52Z DEBUG Destroyed connection context.ldap2_146012240
2016-07-12T18:51:52Z DEBUG   duration: 1 seconds
2016-07-12T18:51:52Z DEBUG   [35/38]: activating sidgen plugin
2016-07-12T18:51:52Z DEBUG Starting external process
2016-07-12T18:51:52Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpHNifK0' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpu7gGVO'
2016-07-12T18:51:52Z DEBUG Process finished, return code=0
2016-07-12T18:51:52Z DEBUG stdout=add objectclass:
	top
	nsSlapdPlugin
	extensibleObject
add cn:
	IPA SIDGEN
add nsslapd-pluginpath:
	libipa_sidgen
add nsslapd-plugininitfunc:
	ipa_sidgen_init
add nsslapd-plugintype:
	postoperation
add nsslapd-pluginenabled:
	on
add nsslapd-pluginid:
	ipa_sidgen_postop
add nsslapd-pluginversion:
	1.0
add nsslapd-pluginvendor:
	Red Hat, Inc.
add nsslapd-plugindescription:
	IPA SIDGEN post operation
add nsslapd-plugin-depends-on-type:
	database
add nsslapd-basedn:
	dc=rsinc,dc=local
adding new entry "cn=IPA SIDGEN,cn=plugins,cn=config"
modify complete


2016-07-12T18:51:52Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:52Z DEBUG   duration: 0 seconds
2016-07-12T18:51:52Z DEBUG   [36/38]: activating extdom plugin
2016-07-12T18:51:52Z DEBUG Starting external process
2016-07-12T18:51:52Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpIyfltw' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpk7JxMO'
2016-07-12T18:51:52Z DEBUG Process finished, return code=0
2016-07-12T18:51:52Z DEBUG stdout=add objectclass:
	top
	nsSlapdPlugin
	extensibleObject
add cn:
	ipa_extdom_extop
add nsslapd-pluginpath:
	libipa_extdom_extop
add nsslapd-plugininitfunc:
	ipa_extdom_init
add nsslapd-plugintype:
	extendedop
add nsslapd-pluginenabled:
	on
add nsslapd-pluginid:
	ipa_extdom_extop
add nsslapd-pluginversion:
	1.0
add nsslapd-pluginvendor:
	RedHat
add nsslapd-plugindescription:
	Support resolving IDs in trusted domains to names and back
add nsslapd-plugin-depends-on-type:
	database
add nsslapd-basedn:
	dc=rsinc,dc=local
adding new entry "cn=ipa_extdom_extop,cn=plugins,cn=config"
modify complete


2016-07-12T18:51:52Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:51:52Z DEBUG   duration: 0 seconds
2016-07-12T18:51:52Z DEBUG   [37/38]: tuning directory server
2016-07-12T18:51:52Z DEBUG Starting external process
2016-07-12T18:51:52Z DEBUG args='/usr/sbin/selinuxenabled'
2016-07-12T18:51:52Z DEBUG Process finished, return code=0
2016-07-12T18:51:52Z DEBUG stdout=
2016-07-12T18:51:52Z DEBUG stderr=
2016-07-12T18:51:52Z DEBUG Starting external process
2016-07-12T18:51:52Z DEBUG args='/sbin/restorecon' '/etc/sysconfig/dirsrv.systemd'
2016-07-12T18:51:52Z DEBUG Process finished, return code=0
2016-07-12T18:51:52Z DEBUG stdout=
2016-07-12T18:51:52Z DEBUG stderr=
2016-07-12T18:51:52Z DEBUG Starting external process
2016-07-12T18:51:52Z DEBUG args='/bin/systemctl' '--system' 'daemon-reload'
2016-07-12T18:51:52Z DEBUG Process finished, return code=0
2016-07-12T18:51:52Z DEBUG stdout=
2016-07-12T18:51:52Z DEBUG stderr=
2016-07-12T18:51:52Z DEBUG Starting external process
2016-07-12T18:51:52Z DEBUG args='/bin/systemctl' '--system' 'daemon-reload'
2016-07-12T18:51:52Z DEBUG Process finished, return code=0
2016-07-12T18:51:52Z DEBUG stdout=
2016-07-12T18:51:52Z DEBUG stderr=
2016-07-12T18:51:52Z DEBUG Starting external process
2016-07-12T18:51:52Z DEBUG args='/bin/systemctl' 'restart' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:52:01Z DEBUG Process finished, return code=0
2016-07-12T18:52:01Z DEBUG stdout=
2016-07-12T18:52:01Z DEBUG stderr=
2016-07-12T18:52:01Z DEBUG Starting external process
2016-07-12T18:52:01Z DEBUG args='/bin/systemctl' 'is-active' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:52:01Z DEBUG Process finished, return code=0
2016-07-12T18:52:01Z DEBUG stdout=active

2016-07-12T18:52:01Z DEBUG stderr=
2016-07-12T18:52:01Z DEBUG wait_for_open_ports: localhost [389] timeout 300
2016-07-12T18:52:02Z DEBUG Starting external process
2016-07-12T18:52:02Z DEBUG args='/bin/systemctl' 'is-active' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:52:02Z DEBUG Process finished, return code=0
2016-07-12T18:52:02Z DEBUG stdout=active

2016-07-12T18:52:02Z DEBUG stderr=
2016-07-12T18:52:02Z DEBUG Starting external process
2016-07-12T18:52:02Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpBnJ9Ee' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpYQYFCf'
2016-07-12T18:52:02Z DEBUG Process finished, return code=0
2016-07-12T18:52:02Z DEBUG stdout=replace nsslapd-maxdescriptors:
	8192
replace nsslapd-reservedescriptors:
	64
modifying entry "cn=config"
modify complete


2016-07-12T18:52:02Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )

2016-07-12T18:52:02Z DEBUG   duration: 10 seconds
2016-07-12T18:52:02Z DEBUG   [38/38]: configuring directory to start on boot
2016-07-12T18:52:02Z DEBUG Starting external process
2016-07-12T18:52:02Z DEBUG args='/bin/systemctl' 'is-enabled' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:52:02Z DEBUG Process finished, return code=0
2016-07-12T18:52:02Z DEBUG stdout=enabled

2016-07-12T18:52:02Z DEBUG stderr=
2016-07-12T18:52:02Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:02Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:02Z DEBUG Starting external process
2016-07-12T18:52:02Z DEBUG args='/bin/systemctl' 'disable' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:52:02Z DEBUG Process finished, return code=0
2016-07-12T18:52:02Z DEBUG stdout=
2016-07-12T18:52:02Z DEBUG stderr=Removed symlink /etc/systemd/system/dirsrv.target.wants/dirsrv at RSINC-LOCAL.service.

2016-07-12T18:52:02Z DEBUG   duration: 0 seconds
2016-07-12T18:52:02Z DEBUG Done configuring directory server (dirsrv).
2016-07-12T18:52:03Z DEBUG flushing ldaps://ipa01-aws.rsinc.local:636 from SchemaCache
2016-07-12T18:52:03Z DEBUG retrieving schema for SchemaCache url=ldaps://ipa01-aws.rsinc.local:636 conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x81dfcb0>
2016-07-12T18:52:04Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:04Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:52:04Z DEBUG raw: dnszone_show(u'242.0.40.10.in-addr.arpa.', version=u'2.156')
2016-07-12T18:52:04Z DEBUG dnszone_show(<DNS name 242.0.40.10.in-addr.arpa.>, rights=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:04Z DEBUG raw: dnszone_show(u'0.40.10.in-addr.arpa.', version=u'2.156')
2016-07-12T18:52:04Z DEBUG dnszone_show(<DNS name 0.40.10.in-addr.arpa.>, rights=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:04Z DEBUG raw: dnsrecord_add(u'rsinc.local', u'_ldap._tcp', srvrecord=u'0 100 389 ipa03-aws', version=u'2.156')
2016-07-12T18:52:04Z DEBUG dnsrecord_add(<DNS name rsinc.local.>, <DNS name _ldap._tcp>, a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=(u'0 100 389 ipa03-aws',), force=False, structured=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:06Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:06Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:06Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:06Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:06Z DEBUG raw: dnsrecord_add(u'rsinc.local', u'_kerberos._tcp', srvrecord=u'0 100 88 ipa03-aws', version=u'2.156')
2016-07-12T18:52:06Z DEBUG dnsrecord_add(<DNS name rsinc.local.>, <DNS name _kerberos._tcp>, a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=(u'0 100 88 ipa03-aws',), force=False, structured=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:07Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:07Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:07Z DEBUG raw: dnsrecord_add(u'rsinc.local', u'_kerberos._udp', srvrecord=u'0 100 88 ipa03-aws', version=u'2.156')
2016-07-12T18:52:07Z DEBUG dnsrecord_add(<DNS name rsinc.local.>, <DNS name _kerberos._udp>, a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=(u'0 100 88 ipa03-aws',), force=False, structured=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:08Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:08Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:08Z DEBUG raw: dnsrecord_add(u'rsinc.local', u'_kerberos-master._tcp', srvrecord=u'0 100 88 ipa03-aws', version=u'2.156')
2016-07-12T18:52:08Z DEBUG dnsrecord_add(<DNS name rsinc.local.>, <DNS name _kerberos-master._tcp>, a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=(u'0 100 88 ipa03-aws',), force=False, structured=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:09Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:09Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:09Z DEBUG raw: dnsrecord_add(u'rsinc.local', u'_kerberos-master._udp', srvrecord=u'0 100 88 ipa03-aws', version=u'2.156')
2016-07-12T18:52:09Z DEBUG dnsrecord_add(<DNS name rsinc.local.>, <DNS name _kerberos-master._udp>, a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=(u'0 100 88 ipa03-aws',), force=False, structured=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:10Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:10Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:10Z DEBUG raw: dnsrecord_add(u'rsinc.local', u'_kpasswd._tcp', srvrecord=u'0 100 464 ipa03-aws', version=u'2.156')
2016-07-12T18:52:10Z DEBUG dnsrecord_add(<DNS name rsinc.local.>, <DNS name _kpasswd._tcp>, a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=(u'0 100 464 ipa03-aws',), force=False, structured=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:11Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:11Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:11Z DEBUG raw: dnsrecord_add(u'rsinc.local', u'_kpasswd._udp', srvrecord=u'0 100 464 ipa03-aws', version=u'2.156')
2016-07-12T18:52:11Z DEBUG dnsrecord_add(<DNS name rsinc.local.>, <DNS name _kpasswd._udp>, a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=(u'0 100 464 ipa03-aws',), force=False, structured=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:12Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:12Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:12Z DEBUG raw: dnsrecord_add(u'rsinc.local', u'_ntp._udp', srvrecord=u'0 100 123 ipa03-aws', version=u'2.156')
2016-07-12T18:52:12Z DEBUG dnsrecord_add(<DNS name rsinc.local.>, <DNS name _ntp._udp>, a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=(u'0 100 123 ipa03-aws',), force=False, structured=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:15Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:15Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:15Z DEBUG raw: dnszone_show(u'rsinc.local', version=u'2.156')
2016-07-12T18:52:15Z DEBUG dnszone_show(<DNS name rsinc.local.>, rights=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:15Z DEBUG raw: dnsrecord_add(u'rsinc.local', u'ipa03-aws', arecord=u'1', version=u'2.156')
2016-07-12T18:52:15Z DEBUG dnsrecord_add(<DNS name rsinc.local.>, <DNS name ipa03-aws>, arecord=(u'1',), a_extra_create_reverse=False, aaaa_extra_create_reverse=False, force=False, structured=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:15Z INFO Replica DNS records could not be added on master: invalid 'ip_address': Gettext('invalid IP address format', domain='ipa', localedir=None)
2016-07-12T18:52:15Z DEBUG Destroyed connection context.ldap2_90329936
2016-07-12T18:52:15Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:15Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:52:15Z DEBUG Starting external process
2016-07-12T18:52:15Z DEBUG args='keyctl' 'get_persistent' '@s' '0'
2016-07-12T18:52:15Z DEBUG Process finished, return code=0
2016-07-12T18:52:15Z DEBUG stdout=173686621

2016-07-12T18:52:15Z DEBUG stderr=
2016-07-12T18:52:15Z DEBUG Enabling persistent keyring CCACHE
2016-07-12T18:52:15Z DEBUG Starting external process
2016-07-12T18:52:15Z DEBUG args='/bin/systemctl' 'is-active' 'krb5kdc.service'
2016-07-12T18:52:15Z DEBUG Process finished, return code=3
2016-07-12T18:52:15Z DEBUG stdout=unknown

2016-07-12T18:52:15Z DEBUG stderr=
2016-07-12T18:52:15Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:15Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:15Z DEBUG Starting external process
2016-07-12T18:52:15Z DEBUG args='/bin/systemctl' 'stop' 'krb5kdc.service'
2016-07-12T18:52:15Z DEBUG Process finished, return code=0
2016-07-12T18:52:15Z DEBUG stdout=
2016-07-12T18:52:15Z DEBUG stderr=
2016-07-12T18:52:15Z DEBUG Configuring Kerberos KDC (krb5kdc). Estimated time: 30 seconds
2016-07-12T18:52:15Z DEBUG   [1/8]: adding sasl mappings to the directory
2016-07-12T18:52:15Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-RSINC-LOCAL.socket from SchemaCache
2016-07-12T18:52:15Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-RSINC-LOCAL.socket conn=<ldap.ldapobject.SimpleLDAPObject instance at 0xaa60ab8>
2016-07-12T18:52:16Z DEBUG   duration: 1 seconds
2016-07-12T18:52:16Z DEBUG   [2/8]: configuring KDC
2016-07-12T18:52:16Z DEBUG Backing up system configuration file '/var/kerberos/krb5kdc/kdc.conf'
2016-07-12T18:52:16Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:52:16Z DEBUG Backing up system configuration file '/etc/krb5.conf'
2016-07-12T18:52:16Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:52:16Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krb5.ini'
2016-07-12T18:52:16Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:52:16Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krb.con'
2016-07-12T18:52:16Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:52:16Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krbrealm.con'
2016-07-12T18:52:16Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:52:16Z DEBUG Starting external process
2016-07-12T18:52:16Z DEBUG args='klist' '-V'
2016-07-12T18:52:16Z DEBUG Process finished, return code=0
2016-07-12T18:52:16Z DEBUG stdout=Kerberos 5 version 1.13.2

2016-07-12T18:52:16Z DEBUG stderr=
2016-07-12T18:52:16Z DEBUG Backing up system configuration file '/etc/sysconfig/krb5kdc'
2016-07-12T18:52:16Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:52:16Z DEBUG Starting external process
2016-07-12T18:52:16Z DEBUG args='/usr/sbin/selinuxenabled'
2016-07-12T18:52:16Z DEBUG Process finished, return code=0
2016-07-12T18:52:16Z DEBUG stdout=
2016-07-12T18:52:16Z DEBUG stderr=
2016-07-12T18:52:16Z DEBUG Starting external process
2016-07-12T18:52:16Z DEBUG args='/sbin/restorecon' '/etc/sysconfig/krb5kdc'
2016-07-12T18:52:16Z DEBUG Process finished, return code=0
2016-07-12T18:52:16Z DEBUG stdout=
2016-07-12T18:52:16Z DEBUG stderr=
2016-07-12T18:52:16Z DEBUG   duration: 0 seconds
2016-07-12T18:52:16Z DEBUG   [3/8]: creating a keytab for the directory
2016-07-12T18:52:16Z DEBUG Starting external process
2016-07-12T18:52:16Z DEBUG args='kadmin.local' '-q' 'addprinc -randkey ldap/ipa03-aws.rsinc.local at RSINC.LOCAL' '-x' 'ipa-setup-override-restrictions'
2016-07-12T18:52:16Z DEBUG Process finished, return code=0
2016-07-12T18:52:16Z DEBUG stdout=Authenticating as principal root/admin at RSINC.LOCAL with password.
Principal "ldap/ipa03-aws.rsinc.local at RSINC.LOCAL" created.

2016-07-12T18:52:16Z DEBUG stderr=WARNING: no policy specified for ldap/ipa03-aws.rsinc.local at RSINC.LOCAL; defaulting to no policy

2016-07-12T18:52:17Z DEBUG Backing up system configuration file '/etc/dirsrv/ds.keytab'
2016-07-12T18:52:17Z DEBUG   -> Not backing up - '/etc/dirsrv/ds.keytab' doesn't exist
2016-07-12T18:52:17Z DEBUG Starting external process
2016-07-12T18:52:17Z DEBUG args='kadmin.local' '-q' 'ktadd -k /etc/dirsrv/ds.keytab ldap/ipa03-aws.rsinc.local at RSINC.LOCAL' '-x' 'ipa-setup-override-restrictions'
2016-07-12T18:52:17Z DEBUG Process finished, return code=0
2016-07-12T18:52:17Z DEBUG stdout=Authenticating as principal root/admin at RSINC.LOCAL with password.
Entry for principal ldap/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/dirsrv/ds.keytab.
Entry for principal ldap/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/dirsrv/ds.keytab.
Entry for principal ldap/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type des3-cbc-sha1 added to keytab WRFILE:/etc/dirsrv/ds.keytab.
Entry for principal ldap/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type arcfour-hmac added to keytab WRFILE:/etc/dirsrv/ds.keytab.
Entry for principal ldap/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/dirsrv/ds.keytab.
Entry for principal ldap/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/dirsrv/ds.keytab.

2016-07-12T18:52:17Z DEBUG stderr=
2016-07-12T18:52:17Z DEBUG   duration: 0 seconds
2016-07-12T18:52:17Z DEBUG   [4/8]: creating a keytab for the machine
2016-07-12T18:52:17Z DEBUG Starting external process
2016-07-12T18:52:17Z DEBUG args='kadmin.local' '-q' 'addprinc -randkey host/ipa03-aws.rsinc.local at RSINC.LOCAL' '-x' 'ipa-setup-override-restrictions'
2016-07-12T18:52:17Z DEBUG Process finished, return code=0
2016-07-12T18:52:17Z DEBUG stdout=Authenticating as principal root/admin at RSINC.LOCAL with password.
Principal "host/ipa03-aws.rsinc.local at RSINC.LOCAL" created.

2016-07-12T18:52:17Z DEBUG stderr=WARNING: no policy specified for host/ipa03-aws.rsinc.local at RSINC.LOCAL; defaulting to no policy

2016-07-12T18:52:17Z DEBUG Backing up system configuration file '/etc/krb5.keytab'
2016-07-12T18:52:17Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:52:17Z DEBUG Starting external process
2016-07-12T18:52:17Z DEBUG args='kadmin.local' '-q' 'ktadd -k /etc/krb5.keytab host/ipa03-aws.rsinc.local at RSINC.LOCAL' '-x' 'ipa-setup-override-restrictions'
2016-07-12T18:52:17Z DEBUG Process finished, return code=0
2016-07-12T18:52:17Z DEBUG stdout=Authenticating as principal root/admin at RSINC.LOCAL with password.
Entry for principal host/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/krb5.keytab.
Entry for principal host/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/krb5.keytab.
Entry for principal host/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type des3-cbc-sha1 added to keytab WRFILE:/etc/krb5.keytab.
Entry for principal host/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type arcfour-hmac added to keytab WRFILE:/etc/krb5.keytab.
Entry for principal host/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/krb5.keytab.
Entry for principal host/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/krb5.keytab.

2016-07-12T18:52:17Z DEBUG stderr=
2016-07-12T18:52:17Z DEBUG   duration: 0 seconds
2016-07-12T18:52:17Z DEBUG   [5/8]: adding the password extension to the directory
2016-07-12T18:52:17Z DEBUG Starting external process
2016-07-12T18:52:17Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpsCS1tk' '-H' 'ldapi://%2fvar%2frun%2fslapd-RSINC-LOCAL.socket' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpO1Mz2N'
2016-07-12T18:52:17Z DEBUG Process finished, return code=0
2016-07-12T18:52:17Z DEBUG stdout=add objectclass:
	top
	nsSlapdPlugin
	extensibleObject
add cn:
	ipa_pwd_extop
add nsslapd-pluginpath:
	libipa_pwd_extop
add nsslapd-plugininitfunc:
	ipapwd_init
add nsslapd-plugintype:
	extendedop
add nsslapd-pluginbetxn:
	on
add nsslapd-pluginenabled:
	on
add nsslapd-pluginid:
	ipa_pwd_extop
add nsslapd-pluginversion:
	1.0
add nsslapd-pluginvendor:
	RedHat
add nsslapd-plugindescription:
	Support saving passwords in multiple formats for different consumers (krb5, samba, freeradius, etc.)
add nsslapd-plugin-depends-on-type:
	database
add nsslapd-realmTree:
	dc=rsinc,dc=local
adding new entry "cn=ipa_pwd_extop,cn=plugins,cn=config"
modify complete


2016-07-12T18:52:17Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-RSINC-LOCAL.socket/??base )

2016-07-12T18:52:17Z DEBUG   duration: 0 seconds
2016-07-12T18:52:17Z DEBUG   [6/8]: enable GSSAPI for replication
2016-07-12T18:52:18Z DEBUG flushing ldaps://ipa03-aws.rsinc.local:636 from SchemaCache
2016-07-12T18:52:18Z DEBUG retrieving schema for SchemaCache url=ldaps://ipa03-aws.rsinc.local:636 conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x7fa07e8>
2016-07-12T18:52:18Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:19Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:20Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:20Z DEBUG flushing ldaps://ipa01-aws.rsinc.local:636 from SchemaCache
2016-07-12T18:52:20Z DEBUG retrieving schema for SchemaCache url=ldaps://ipa01-aws.rsinc.local:636 conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x7fbf710>
2016-07-12T18:52:22Z INFO Setting agreement cn=meToipa03-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:24Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa03-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:26Z INFO Replication Update in progress: FALSE: status: 0 Replica acquired successfully: Incremental update succeeded: start: 0: end: 0
2016-07-12T18:52:26Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:26Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:26Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:28Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:29Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:29Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:29Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:29Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:30Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:31Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:31Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:31Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:31Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:32Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:33Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:33Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:33Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:33Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:34Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:35Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:35Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:35Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:35Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:36Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:37Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:37Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:38Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:38Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:39Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:40Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:40Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:40Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:40Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:41Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:42Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:42Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:42Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:42Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:43Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:44Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:44Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:45Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:45Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:46Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:47Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:47Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:47Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:47Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:48Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:49Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:49Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:49Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:49Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:50Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:51Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:51Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:51Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:51Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:52Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:53Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:53Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:53Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:53Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:54Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:55Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:55Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:55Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:55Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:56Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:57Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:57Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:57Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:57Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:58Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:59Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:59Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:59Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:59Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:00Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:01Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:01Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:02Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:02Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:03Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:04Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:04Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:05Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:05Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:06Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:07Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:07Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:07Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:07Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:08Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:09Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:09Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:09Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:09Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:10Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:11Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:11Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:11Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:11Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:12Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:13Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:13Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:13Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:13Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:14Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:15Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:15Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:15Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:15Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:16Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:17Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:17Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:17Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:17Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:18Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:19Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:19Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:19Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:19Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:20Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:21Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:21Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:22Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:22Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:23Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:24Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:24Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:24Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:24Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:25Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:26Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:26Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:26Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:26Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:27Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:28Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:28Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:29Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:29Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:30Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:31Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:31Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:31Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:31Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:32Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:33Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:33Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:33Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:33Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:34Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:35Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:35Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:36Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:36Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:37Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:38Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:38Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:38Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:38Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:39Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:40Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:40Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:41Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:41Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:42Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:43Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:43Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:43Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:43Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:44Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:45Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:45Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:45Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:45Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:46Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:47Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:47Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:47Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:47Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:48Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:49Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:49Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:49Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:49Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:50Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:51Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:51Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:52Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:52Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:53Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:54Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:54Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:54Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:54Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:55Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:56Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:56Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:57Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:57Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:58Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:59Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:59Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:59Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:59Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:00Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:01Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:01Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:01Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:01Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:02Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:03Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:03Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:03Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:03Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:04Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:05Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:05Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:05Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:05Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:06Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:07Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:07Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:08Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:08Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:09Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:10Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:10Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:10Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:10Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:11Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:12Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:12Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:12Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:12Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:13Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:14Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:14Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:15Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:15Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:16Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:17Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:17Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:17Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:17Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:18Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:19Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:19Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:19Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:19Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:20Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:21Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:21Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:21Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:21Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:22Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:23Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:23Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:23Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:23Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:24Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:25Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:25Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:26Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:26Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:27Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:28Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:28Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:28Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:28Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:29Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:30Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:30Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:30Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:30Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:31Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:32Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:32Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:32Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:32Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:33Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:34Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:34Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:35Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:35Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:36Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:37Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:37Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:37Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:37Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:38Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:39Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:39Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:39Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:39Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:40Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:41Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:41Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:41Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:41Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:42Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:43Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:43Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:43Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:43Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:44Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:45Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:45Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:46Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:46Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:47Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:48Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:48Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:49Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:49Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:50Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:51Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:51Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:51Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:51Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:52Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:53Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:53Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:54Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:54Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:55Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:56Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:56Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:56Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:56Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:57Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:58Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:58Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:58Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:58Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:59Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:00Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:00Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:00Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:00Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:01Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:02Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:02Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:02Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:02Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:03Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:04Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:04Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:04Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:04Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:05Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:06Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:06Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:07Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:07Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:08Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:09Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:09Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:09Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:09Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:10Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:11Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:11Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:11Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:11Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:12Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:13Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:13Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:13Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:13Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:14Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:15Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:15Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:15Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:15Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:16Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:17Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:17Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:17Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:17Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:18Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:19Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:19Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:19Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:19Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:20Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:21Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:21Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:21Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:21Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:23Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:24Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:24Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:24Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:24Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:25Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:26Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:26Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:26Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:26Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:27Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:28Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:28Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:28Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:28Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:29Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:30Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:30Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:30Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:30Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:31Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:32Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:32Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:32Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:32Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:33Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:34Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:34Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:35Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:35Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:36Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:37Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:37Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:37Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:37Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:38Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:39Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:39Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:39Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:39Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:40Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:41Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:41Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:41Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:41Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:42Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:44Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:44Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:44Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:44Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:45Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:46Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:46Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:46Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:46Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:47Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:48Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:48Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:49Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:49Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:50Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:51Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:51Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:51Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:51Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:52Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:53Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:53Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:53Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:53Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:54Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:55Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:55Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:55Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:55Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:56Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:57Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:57Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:57Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:57Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:58Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:59Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:59Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:59Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:59Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:56:00Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:56:01Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:56:01Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:56:01Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:56:01Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:56:02Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:56:03Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:56:03Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:56:04Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:56:04Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:56:05Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:56:06Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:56:06Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:56:06Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:56:06Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:56:07Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:56:08Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:56:08Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:56:09Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:56:09Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:56:10Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:56:11Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:56:11Z DEBUG Traceback (most recent call last):
  File "/usr/lib/python2.7/site-packages/ipaserver/install/service.py", line 418, in start_creation
    run_step(full_msg, method)
  File "/usr/lib/python2.7/site-packages/ipaserver/install/service.py", line 408, in run_step
    method()
  File "/usr/lib/python2.7/site-packages/ipaserver/install/krbinstance.py", line 438, in __convert_to_gssapi_replication
    r_bindpw=self.dm_password)
  File "/usr/lib/python2.7/site-packages/ipaserver/install/replication.py", line 1104, in convert_to_gssapi_replication
    self.gssapi_update_agreements(self.conn, r_conn)
  File "/usr/lib/python2.7/site-packages/ipaserver/install/replication.py", line 797, in gssapi_update_agreements
    self.setup_krb_princs_as_replica_binddns(a, b)
  File "/usr/lib/python2.7/site-packages/ipaserver/install/replication.py", line 767, in setup_krb_princs_as_replica_binddns
    (a_dn, b_dn) = self.get_replica_principal_dns(a, b, retries=100)
  File "/usr/lib/python2.7/site-packages/ipaserver/install/replication.py", line 751, in get_replica_principal_dns
    raise RuntimeError(error)
RuntimeError: One of the ldap service principals is missing. Replication agreement cannot be converted.
Replication error message: Can't acquire busy replica

2016-07-12T18:56:11Z DEBUG   [error] RuntimeError: One of the ldap service principals is missing. Replication agreement cannot be converted.
Replication error message: Can't acquire busy replica
2016-07-12T18:56:11Z DEBUG   File "/usr/lib/python2.7/site-packages/ipapython/admintool.py", line 171, in execute
    return_value = self.run()
  File "/usr/lib/python2.7/site-packages/ipapython/install/cli.py", line 311, in run
    cfgr.run()
  File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 281, in run
    self.execute()
  File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 303, in execute
    for nothing in self._executor():
  File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 343, in __runner
    self._handle_exception(exc_info)
  File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 365, in _handle_exception
    util.raise_exc_info(exc_info)
  File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 333, in __runner
    step()
  File "/usr/lib/python2.7/site-packages/ipapython/install/util.py", line 87, in run_generator_with_yield_from
    raise_exc_info(exc_info)
  File "/usr/lib/python2.7/site-packages/ipapython/install/util.py", line 65, in run_generator_with_yield_from
    value = gen.send(prev_value)
  File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 539, in _configure
    executor.next()
  File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 343, in __runner
    self._handle_exception(exc_info)
  File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 421, in _handle_exception
    self.__parent._handle_exception(exc_info)
  File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 365, in _handle_exception
    util.raise_exc_info(exc_info)
  File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 418, in _handle_exception
    super(ComponentBase, self)._handle_exception(exc_info)
  File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 365, in _handle_exception
    util.raise_exc_info(exc_info)
  File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 333, in __runner
    step()
  File "/usr/lib/python2.7/site-packages/ipapython/install/util.py", line 87, in run_generator_with_yield_from
    raise_exc_info(exc_info)
  File "/usr/lib/python2.7/site-packages/ipapython/install/util.py", line 65, in run_generator_with_yield_from
    value = gen.send(prev_value)
  File "/usr/lib/python2.7/site-packages/ipapython/install/common.py", line 63, in _install
    for nothing in self._installer(self.parent):
  File "/usr/lib/python2.7/site-packages/ipaserver/install/server/replicainstall.py", line 901, in main
    install(self)
  File "/usr/lib/python2.7/site-packages/ipaserver/install/server/replicainstall.py", line 295, in decorated
    func(installer)
  File "/usr/lib/python2.7/site-packages/ipaserver/install/server/replicainstall.py", line 618, in install
    krb = install_krb(config, setup_pkinit=not options.no_pkinit)
  File "/usr/lib/python2.7/site-packages/ipaserver/install/server/replicainstall.py", line 93, in install_krb
    setup_pkinit, pkcs12_info)
  File "/usr/lib/python2.7/site-packages/ipaserver/install/krbinstance.py", line 214, in create_replica
    self.start_creation(runtime=30)
  File "/usr/lib/python2.7/site-packages/ipaserver/install/service.py", line 418, in start_creation
    run_step(full_msg, method)
  File "/usr/lib/python2.7/site-packages/ipaserver/install/service.py", line 408, in run_step
    method()
  File "/usr/lib/python2.7/site-packages/ipaserver/install/krbinstance.py", line 438, in __convert_to_gssapi_replication
    r_bindpw=self.dm_password)
  File "/usr/lib/python2.7/site-packages/ipaserver/install/replication.py", line 1104, in convert_to_gssapi_replication
    self.gssapi_update_agreements(self.conn, r_conn)
  File "/usr/lib/python2.7/site-packages/ipaserver/install/replication.py", line 797, in gssapi_update_agreements
    self.setup_krb_princs_as_replica_binddns(a, b)
  File "/usr/lib/python2.7/site-packages/ipaserver/install/replication.py", line 767, in setup_krb_princs_as_replica_binddns
    (a_dn, b_dn) = self.get_replica_principal_dns(a, b, retries=100)
  File "/usr/lib/python2.7/site-packages/ipaserver/install/replication.py", line 751, in get_replica_principal_dns
    raise RuntimeError(error)

2016-07-12T18:56:11Z DEBUG The ipa-replica-install command failed, exception: RuntimeError: One of the ldap service principals is missing. Replication agreement cannot be converted.
Replication error message: Can't acquire busy replica
2016-07-12T18:56:11Z ERROR One of the ldap service principals is missing. Replication agreement cannot be converted.
Replication error message: Can't acquire busy replica


More information about the Freeipa-users mailing list