[Freeipa-users] FreeIPA (Add Replica fails on GSSAPI)
Devin Acosta
linuxguru.co at gmail.com
Tue Jul 12 19:34:46 UTC 2016
I am trying to add a 4th replica to my FreeIPA installation. I am running
the latest CentOS 7.2 (full updates) and i have tried multiple times and
fails every time in same location. When it fails I remove the replication
agreements and try again and keeps failing in same location.
[root at ipa03-aws centos]# ipa-replica-install
replica-info-ipa03-aws.rsinc.local.gpg
WARNING: conflicting time&date synchronization service 'chronyd' will
be disabled in favor of ntpd
Directory Manager (existing master) password:
Run connection check to master
Check connection from replica to remote master 'ipa01-aws.rsinc.local':
Directory Service: Unsecure port (389): OK
Directory Service: Secure port (636): OK
Kerberos KDC: TCP (88): OK
Kerberos Kpasswd: TCP (464): OK
HTTP Server: Unsecure port (80): OK
HTTP Server: Secure port (443): OK
The following list of ports use UDP protocol and would need to be
checked manually:
Kerberos KDC: UDP (88): SKIPPED
Kerberos Kpasswd: UDP (464): SKIPPED
Connection from replica to master is OK.
Start listening on required ports for remote master check
Get credentials to log in to remote master
admin at RSINC.LOCAL password:
Check SSH connection to remote master
Execute check on remote master
Check connection from master to remote replica 'ipa03-aws.rsinc.local':
Directory Service: Unsecure port (389): OK
Directory Service: Secure port (636): OK
Kerberos KDC: TCP (88): OK
Kerberos KDC: UDP (88): OK
Kerberos Kpasswd: TCP (464): OK
Kerberos Kpasswd: UDP (464): OK
HTTP Server: Unsecure port (80): OK
HTTP Server: Secure port (443): OK
Connection from master to replica is OK.
Connection check OK
Configuring NTP daemon (ntpd)
[1/4]: stopping ntpd
[2/4]: writing configuration
[3/4]: configuring ntpd to start on boot
[4/4]: starting ntpd
Done configuring NTP daemon (ntpd).
Configuring directory server (dirsrv). Estimated time: 1 minute
[1/38]: creating directory server user
[2/38]: creating directory server instance
[3/38]: adding default schema
[4/38]: enabling memberof plugin
[5/38]: enabling winsync plugin
[6/38]: configuring replication version plugin
[7/38]: enabling IPA enrollment plugin
[8/38]: enabling ldapi
[9/38]: configuring uniqueness plugin
[10/38]: configuring uuid plugin
[11/38]: configuring modrdn plugin
[12/38]: configuring DNS plugin
[13/38]: enabling entryUSN plugin
[14/38]: configuring lockout plugin
[15/38]: creating indices
[16/38]: enabling referential integrity plugin
[17/38]: configuring ssl for ds instance
[18/38]: configuring certmap.conf
[19/38]: configure autobind for root
[20/38]: configure new location for managed entries
[21/38]: configure dirsrv ccache
[22/38]: enable SASL mapping fallback
[23/38]: restarting directory server
[24/38]: setting up initial replication
Starting replication, please wait until this has completed.
Update in progress, 4 seconds elapsed
Update succeeded
[25/38]: updating schema
[26/38]: setting Auto Member configuration
[27/38]: enabling S4U2Proxy delegation
[28/38]: importing CA certificates from LDAP
[29/38]: initializing group membership
[30/38]: adding master entry
[31/38]: initializing domain level
[32/38]: configuring Posix uid/gid generation
[33/38]: adding replication acis
[34/38]: enabling compatibility plugin
[35/38]: activating sidgen plugin
[36/38]: activating extdom plugin
[37/38]: tuning directory server
[38/38]: configuring directory to start on boot
Done configuring directory server (dirsrv).
Configuring Kerberos KDC (krb5kdc). Estimated time: 30 seconds
[1/8]: adding sasl mappings to the directory
[2/8]: configuring KDC
[3/8]: creating a keytab for the directory
[4/8]: creating a keytab for the machine
[5/8]: adding the password extension to the directory
[6/8]: enable GSSAPI for replication
[error] RuntimeError: One of the ldap service principals is missing.
Replication agreement cannot be converted.
Replication error message: Can't acquire busy replica
Your system may be partly configured.
Run /usr/sbin/ipa-server-install --uninstall to clean up.
ipa.ipapython.install.cli.install_tool(Replica): ERROR One of the ldap
service principals is missing. Replication agreement cannot be converted.
Replication error message: Can't acquire busy replica
Please see attached file for the full log file.
Any help would be appreciated!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20160712/f3dccfc0/attachment.htm>
-------------- next part --------------
2016-07-12T18:50:11Z DEBUG Logging to /var/log/ipareplica-install.log
2016-07-12T18:50:11Z DEBUG ipa-replica-install was invoked with arguments ['replica-info-ipa03-aws.rsinc.local.gpg'] and options: {'no_dns_sshfp': None, 'skip_schema_check': None, 'no_ntp': None, 'setup_kra': None, 'ip_addresses': None, 'mkhomedir': None, 'setup_ca': None, 'no_pkinit': None, 'verbose': False, 'no_forwarders': None, 'ssh_trust_dns': None, 'setup_dns': None, 'no_reverse': None, 'reverse_zones': None, 'unattended': False, 'no_host_dns': None, 'no_sshd': None, 'no_ui_redirect': None, 'forwarders': None, 'skip_conncheck': None, 'no_ssh': None, 'quiet': False, 'no_dnssec_validation': None, 'log_file': None}
2016-07-12T18:50:11Z DEBUG IPA version 4.2.0-15.0.1.el7.centos.17
2016-07-12T18:50:11Z DEBUG Starting external process
2016-07-12T18:50:11Z DEBUG args='/usr/sbin/selinuxenabled'
2016-07-12T18:50:11Z DEBUG Process finished, return code=0
2016-07-12T18:50:11Z DEBUG stdout=
2016-07-12T18:50:11Z DEBUG stderr=
2016-07-12T18:50:11Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index'
2016-07-12T18:50:11Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:50:11Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:50:11Z DEBUG Starting external process
2016-07-12T18:50:11Z DEBUG args='/usr/sbin/httpd' '-t' '-D' 'DUMP_VHOSTS'
2016-07-12T18:50:11Z DEBUG Process finished, return code=0
2016-07-12T18:50:11Z DEBUG stdout=VirtualHost configuration:
*:8443 ipa03-aws.rsinc.local (/etc/httpd/conf.d/nss.conf:83)
2016-07-12T18:50:11Z DEBUG stderr=
2016-07-12T18:50:11Z DEBUG Starting external process
2016-07-12T18:50:11Z DEBUG args='/bin/systemctl' 'is-enabled' 'chronyd.service'
2016-07-12T18:50:11Z DEBUG Process finished, return code=0
2016-07-12T18:50:11Z DEBUG stdout=enabled
2016-07-12T18:50:11Z DEBUG stderr=
2016-07-12T18:50:14Z DEBUG Starting external process
2016-07-12T18:50:14Z DEBUG args='/usr/bin/gpg-agent' '--batch' '--homedir' '/tmp/tmp34bUDTipa/ipa-MkvnMP/.gnupg' '--daemon' '/usr/bin/gpg' '--batch' '--homedir' '/tmp/tmp34bUDTipa/ipa-MkvnMP/.gnupg' '--passphrase-fd' '0' '--yes' '--no-tty' '-o' '/tmp/tmp34bUDTipa/files.tar' '-d' 'replica-info-ipa03-aws.rsinc.local.gpg'
2016-07-12T18:50:14Z DEBUG Process finished, return code=0
2016-07-12T18:50:14Z DEBUG Starting external process
2016-07-12T18:50:14Z DEBUG args='tar' 'xf' '/tmp/tmp34bUDTipa/files.tar' '-C' '/tmp/tmp34bUDTipa'
2016-07-12T18:50:14Z DEBUG Process finished, return code=0
2016-07-12T18:50:14Z DEBUG stdout=
2016-07-12T18:50:14Z DEBUG stderr=
2016-07-12T18:50:14Z DEBUG Installing replica file with version 40200 (0 means no version in prepared file).
2016-07-12T18:50:14Z DEBUG Check if ipa03-aws.rsinc.local is a primary hostname for localhost
2016-07-12T18:50:14Z DEBUG Primary hostname for localhost: ipa03-aws.rsinc.local
2016-07-12T18:50:14Z DEBUG Search DNS for ipa03-aws.rsinc.local
2016-07-12T18:50:14Z DEBUG Check if ipa03-aws.rsinc.local is not a CNAME
2016-07-12T18:50:15Z DEBUG Check reverse address of 10.40.0.242
2016-07-12T18:50:15Z DEBUG Found reverse name: ipa03-aws.rsinc.local
2016-07-12T18:50:15Z DEBUG importing all plugin modules in ipalib.plugins...
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.aci
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.automember
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.automount
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.baseldap
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.baseuser
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.batch
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.caacl
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.cert
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.certprofile
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.config
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.delegation
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.dns
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.domainlevel
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.group
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.hbacrule
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.hbacsvc
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.hbacsvcgroup
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.hbactest
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.host
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.hostgroup
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.idrange
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.idviews
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.internal
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.kerberos
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.krbtpolicy
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.migration
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.misc
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.netgroup
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.otpconfig
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.otptoken
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.otptoken_yubikey
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.passwd
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.permission
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.ping
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.pkinit
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.privilege
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.pwpolicy
2016-07-12T18:50:15Z DEBUG Starting external process
2016-07-12T18:50:15Z DEBUG args='klist' '-V'
2016-07-12T18:50:15Z DEBUG Process finished, return code=0
2016-07-12T18:50:15Z DEBUG stdout=Kerberos 5 version 1.13.2
2016-07-12T18:50:15Z DEBUG stderr=
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.radiusproxy
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.realmdomains
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.role
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.rpcclient
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.selfservice
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.selinuxusermap
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.server
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.service
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.servicedelegation
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.session
2016-07-12T18:50:15Z WARNING session memcached servers not running
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.stageuser
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.sudocmd
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.sudocmdgroup
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.sudorule
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.topology
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.trust
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.user
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.vault
2016-07-12T18:50:15Z DEBUG importing plugin module ipalib.plugins.virtual
2016-07-12T18:50:15Z DEBUG importing all plugin modules in ipaserver.plugins...
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.plugins.dogtag
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.plugins.join
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.plugins.ldap2
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.plugins.rabase
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.plugins.xmlserver
2016-07-12T18:50:15Z DEBUG importing all plugin modules in ipaserver.install.plugins...
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.adtrust
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.dns
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.update_nis
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.update_referint
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.update_services
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness
2016-07-12T18:50:15Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt
2016-07-12T18:50:15Z DEBUG SessionAuthManager.register: name=jsonserver_session_59557136
2016-07-12T18:50:15Z DEBUG SessionAuthManager.register: name=xmlserver_session_59559568
2016-07-12T18:50:15Z DEBUG Mounting ipaserver.rpcserver.jsonserver_kerb() at '/json'
2016-07-12T18:50:15Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:15Z DEBUG Mounting ipaserver.rpcserver.xmlserver_session() at '/session/xml'
2016-07-12T18:50:15Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:15Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:15Z DEBUG Mounting ipaserver.rpcserver.sync_token() at '/session/sync_token'
2016-07-12T18:50:15Z DEBUG Mounting ipaserver.rpcserver.xmlserver() at '/xml'
2016-07-12T18:50:15Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:15Z DEBUG Mounting ipaserver.rpcserver.jsonserver_session() at '/session/json'
2016-07-12T18:50:15Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:15Z DEBUG Mounting ipaserver.rpcserver.login_kerberos() at '/session/login_kerberos'
2016-07-12T18:50:15Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:16Z DEBUG Mounting ipaserver.rpcserver.login_password() at '/session/login_password'
2016-07-12T18:50:16Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:16Z DEBUG Mounting ipaserver.rpcserver.change_password() at '/session/change_password'
2016-07-12T18:50:16Z DEBUG Check if ipa01-aws.rsinc.local is a primary hostname for localhost
2016-07-12T18:50:16Z DEBUG Primary hostname for localhost: ipa01-aws.rsinc.local
2016-07-12T18:50:16Z DEBUG Search DNS for ipa01-aws.rsinc.local
2016-07-12T18:50:21Z DEBUG Check if ipa01-aws.rsinc.local is not a CNAME
2016-07-12T18:50:21Z DEBUG Check reverse address of 10.10.0.88
2016-07-12T18:50:21Z DEBUG Found reverse name: ipa01-aws.rsinc.local
2016-07-12T18:50:21Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmprj5lWPipa' '-N' '-f' '/tmp/tmprj5lWPipa/pwdfile.txt'
2016-07-12T18:50:21Z DEBUG Process finished, return code=0
2016-07-12T18:50:21Z DEBUG stdout=
2016-07-12T18:50:21Z DEBUG stderr=
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/pk12util' '-d' '/tmp/tmprj5lWPipa' '-i' '/tmp/tmp34bUDTipa/realm_info/dscert.p12' '-k' '/tmp/tmprj5lWPipa/pwdfile.txt' '-v' '-w' '/dev/stdin'
2016-07-12T18:50:21Z DEBUG Process finished, return code=0
2016-07-12T18:50:21Z DEBUG stdout=pk12util: PKCS12 IMPORT SUCCESSFUL
2016-07-12T18:50:21Z DEBUG stderr=
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmprj5lWPipa' '-L'
2016-07-12T18:50:21Z DEBUG Process finished, return code=0
2016-07-12T18:50:21Z DEBUG stdout=
Certificate Nickname Trust Attributes
SSL,S/MIME,JAR/XPI
Server-Cert u,u,u
RSINC.LOCAL IPA CA ,,
2016-07-12T18:50:21Z DEBUG stderr=
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmprj5lWPipa' '-A' '-n' 'CA 1' '-t' ',,' '-a'
2016-07-12T18:50:21Z DEBUG Process finished, return code=0
2016-07-12T18:50:21Z DEBUG stdout=
2016-07-12T18:50:21Z DEBUG stderr=
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmprj5lWPipa' '-O' '-n' 'Server-Cert'
2016-07-12T18:50:21Z DEBUG Process finished, return code=0
2016-07-12T18:50:21Z DEBUG stdout="RSINC.LOCAL IPA CA" [CN=Certificate Authority,O=RSINC.LOCAL]
"Server-Cert" [CN=ipa03-aws.rsinc.local,O=RSINC.LOCAL]
2016-07-12T18:50:21Z DEBUG stderr=
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmprj5lWPipa' '-M' '-n' 'RSINC.LOCAL IPA CA' '-t' 'CT,C,C'
2016-07-12T18:50:21Z DEBUG Process finished, return code=0
2016-07-12T18:50:21Z DEBUG stdout=
2016-07-12T18:50:21Z DEBUG stderr=
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmprj5lWPipa' '-O' '-n' 'Server-Cert'
2016-07-12T18:50:21Z DEBUG Process finished, return code=0
2016-07-12T18:50:21Z DEBUG stdout="RSINC.LOCAL IPA CA" [CN=Certificate Authority,O=RSINC.LOCAL]
"Server-Cert" [CN=ipa03-aws.rsinc.local,O=RSINC.LOCAL]
2016-07-12T18:50:21Z DEBUG stderr=
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmprj5lWPipa' '-L' '-n' 'RSINC.LOCAL IPA CA' '-a'
2016-07-12T18:50:21Z DEBUG Process finished, return code=0
2016-07-12T18:50:21Z DEBUG stdout=-----BEGIN CERTIFICATE-----
MIIDkTCCAnmgAwIBAgIBATANBgkqhkiG9w0BAQsFADA2MRQwEgYDVQQKDAtSU0lO
Qy5MT0NBTDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE2MDMx
MTE2NDMxNVoXDTM2MDMxMTE2NDMxNVowNjEUMBIGA1UECgwLUlNJTkMuTE9DQUwx
HjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTCCASIwDQYJKoZIhvcNAQEB
BQADggEPADCCAQoCggEBAMeuq3fFabQUU4lMQmLEQmN4ryu3bp6ekaBc/+4txdYg
AYiSUvZOChcS+6l0XWl/d1u5txR5BIKdADCvO9rcIglQbvn1y6scjbmMqzd4xtCE
IN28t1ywPQlWIAGSLw2VDuZ/lmKxmyG00RMxKRvZYuWe/pHZqiza9Rywyt+hjxDK
GjghSMGujqYiGXuDviR79q+g7WFQP+8e3D59NmGa8N9iGHaVOBYiNBJIS9raDWmY
LvpHY5cBUYrhBGsIIia3l+V2a+9RPXceF7dN5b3xVae5BK2r39ohFtzZw6b1StVS
QLeuAexrabVUZEEltzcSUyZo1pZqfsOfyOA5LUWsIsUCAwEAAaOBqTCBpjAfBgNV
HSMEGDAWgBS7H+9FH63CaSCM3WK2HMFJFSqzUjAPBgNVHRMBAf8EBTADAQH/MA4G
A1UdDwEB/wQEAwIBxjAdBgNVHQ4EFgQUux/vRR+twmkgjN1ithzBSRUqs1IwQwYI
KwYBBQUHAQEENzA1MDMGCCsGAQUFBzABhidodHRwOi8vaXBhMDEtYXdzLnJzaW5j
LmxvY2FsOjgwL2NhL29jc3AwDQYJKoZIhvcNAQELBQADggEBAIuAZ1+x3we31MvO
ZRB3fg3F8JVALb8iZ8EMSktNIlW71A6UwlwMwJi/1yGBuTAp6GwgZTKETBJ40hqx
1G7DSXaViXmIf8ERRvM/0LEba+Skokt9N+F+kQeOE340/YEMvUR/uiGaaEurA3dm
WsoJ0z/X401qHLH7XIyTKubI+TK6unVFwO+p6OUb/n+/ZTBPY5CluwsH67qHxAFf
WBsn6fd+2kl10LC6Z/drQ+yPbApn8wo0k1Pvht2w01nFji9z3C6zsk7JG+EJ0l8W
LqXaFqEeRJlG+aPmadqEYDWBE8A05+5euoc8z/zLJXZLWSMs4PpKwcuWlWZ+84gV
N2jzdNA=
-----END CERTIFICATE-----
2016-07-12T18:50:21Z DEBUG stderr=
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmprj5lWPipa' '-L'
2016-07-12T18:50:21Z DEBUG Process finished, return code=0
2016-07-12T18:50:21Z DEBUG stdout=
Certificate Nickname Trust Attributes
SSL,S/MIME,JAR/XPI
Server-Cert u,u,u
RSINC.LOCAL IPA CA CT,C,C
2016-07-12T18:50:21Z DEBUG stderr=
2016-07-12T18:50:21Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpX8lR1Xipa' '-N' '-f' '/tmp/tmpX8lR1Xipa/pwdfile.txt'
2016-07-12T18:50:21Z DEBUG Process finished, return code=0
2016-07-12T18:50:21Z DEBUG stdout=
2016-07-12T18:50:21Z DEBUG stderr=
2016-07-12T18:50:21Z DEBUG Starting external process
2016-07-12T18:50:21Z DEBUG args='/usr/bin/pk12util' '-d' '/tmp/tmpX8lR1Xipa' '-i' '/tmp/tmp34bUDTipa/realm_info/httpcert.p12' '-k' '/tmp/tmpX8lR1Xipa/pwdfile.txt' '-v' '-w' '/dev/stdin'
2016-07-12T18:50:22Z DEBUG Process finished, return code=0
2016-07-12T18:50:22Z DEBUG stdout=pk12util: PKCS12 IMPORT SUCCESSFUL
2016-07-12T18:50:22Z DEBUG stderr=
2016-07-12T18:50:22Z DEBUG Starting external process
2016-07-12T18:50:22Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpX8lR1Xipa' '-L'
2016-07-12T18:50:22Z DEBUG Process finished, return code=0
2016-07-12T18:50:22Z DEBUG stdout=
Certificate Nickname Trust Attributes
SSL,S/MIME,JAR/XPI
Server-Cert u,u,u
RSINC.LOCAL IPA CA ,,
2016-07-12T18:50:22Z DEBUG stderr=
2016-07-12T18:50:22Z DEBUG Starting external process
2016-07-12T18:50:22Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpX8lR1Xipa' '-A' '-n' 'CA 1' '-t' ',,' '-a'
2016-07-12T18:50:22Z DEBUG Process finished, return code=0
2016-07-12T18:50:22Z DEBUG stdout=
2016-07-12T18:50:22Z DEBUG stderr=
2016-07-12T18:50:22Z DEBUG Starting external process
2016-07-12T18:50:22Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpX8lR1Xipa' '-O' '-n' 'Server-Cert'
2016-07-12T18:50:22Z DEBUG Process finished, return code=0
2016-07-12T18:50:22Z DEBUG stdout="RSINC.LOCAL IPA CA" [CN=Certificate Authority,O=RSINC.LOCAL]
"Server-Cert" [CN=ipa03-aws.rsinc.local,O=RSINC.LOCAL]
2016-07-12T18:50:22Z DEBUG stderr=
2016-07-12T18:50:22Z DEBUG Starting external process
2016-07-12T18:50:22Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpX8lR1Xipa' '-M' '-n' 'RSINC.LOCAL IPA CA' '-t' 'CT,C,C'
2016-07-12T18:50:22Z DEBUG Process finished, return code=0
2016-07-12T18:50:22Z DEBUG stdout=
2016-07-12T18:50:22Z DEBUG stderr=
2016-07-12T18:50:22Z DEBUG Starting external process
2016-07-12T18:50:22Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpX8lR1Xipa' '-O' '-n' 'Server-Cert'
2016-07-12T18:50:22Z DEBUG Process finished, return code=0
2016-07-12T18:50:22Z DEBUG stdout="RSINC.LOCAL IPA CA" [CN=Certificate Authority,O=RSINC.LOCAL]
"Server-Cert" [CN=ipa03-aws.rsinc.local,O=RSINC.LOCAL]
2016-07-12T18:50:22Z DEBUG stderr=
2016-07-12T18:50:22Z DEBUG Starting external process
2016-07-12T18:50:22Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpX8lR1Xipa' '-L' '-n' 'RSINC.LOCAL IPA CA' '-a'
2016-07-12T18:50:22Z DEBUG Process finished, return code=0
2016-07-12T18:50:22Z DEBUG stdout=-----BEGIN CERTIFICATE-----
MIIDkTCCAnmgAwIBAgIBATANBgkqhkiG9w0BAQsFADA2MRQwEgYDVQQKDAtSU0lO
Qy5MT0NBTDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE2MDMx
MTE2NDMxNVoXDTM2MDMxMTE2NDMxNVowNjEUMBIGA1UECgwLUlNJTkMuTE9DQUwx
HjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTCCASIwDQYJKoZIhvcNAQEB
BQADggEPADCCAQoCggEBAMeuq3fFabQUU4lMQmLEQmN4ryu3bp6ekaBc/+4txdYg
AYiSUvZOChcS+6l0XWl/d1u5txR5BIKdADCvO9rcIglQbvn1y6scjbmMqzd4xtCE
IN28t1ywPQlWIAGSLw2VDuZ/lmKxmyG00RMxKRvZYuWe/pHZqiza9Rywyt+hjxDK
GjghSMGujqYiGXuDviR79q+g7WFQP+8e3D59NmGa8N9iGHaVOBYiNBJIS9raDWmY
LvpHY5cBUYrhBGsIIia3l+V2a+9RPXceF7dN5b3xVae5BK2r39ohFtzZw6b1StVS
QLeuAexrabVUZEEltzcSUyZo1pZqfsOfyOA5LUWsIsUCAwEAAaOBqTCBpjAfBgNV
HSMEGDAWgBS7H+9FH63CaSCM3WK2HMFJFSqzUjAPBgNVHRMBAf8EBTADAQH/MA4G
A1UdDwEB/wQEAwIBxjAdBgNVHQ4EFgQUux/vRR+twmkgjN1ithzBSRUqs1IwQwYI
KwYBBQUHAQEENzA1MDMGCCsGAQUFBzABhidodHRwOi8vaXBhMDEtYXdzLnJzaW5j
LmxvY2FsOjgwL2NhL29jc3AwDQYJKoZIhvcNAQELBQADggEBAIuAZ1+x3we31MvO
ZRB3fg3F8JVALb8iZ8EMSktNIlW71A6UwlwMwJi/1yGBuTAp6GwgZTKETBJ40hqx
1G7DSXaViXmIf8ERRvM/0LEba+Skokt9N+F+kQeOE340/YEMvUR/uiGaaEurA3dm
WsoJ0z/X401qHLH7XIyTKubI+TK6unVFwO+p6OUb/n+/ZTBPY5CluwsH67qHxAFf
WBsn6fd+2kl10LC6Z/drQ+yPbApn8wo0k1Pvht2w01nFji9z3C6zsk7JG+EJ0l8W
LqXaFqEeRJlG+aPmadqEYDWBE8A05+5euoc8z/zLJXZLWSMs4PpKwcuWlWZ+84gV
N2jzdNA=
-----END CERTIFICATE-----
2016-07-12T18:50:22Z DEBUG stderr=
2016-07-12T18:50:22Z DEBUG Starting external process
2016-07-12T18:50:22Z DEBUG args='/usr/bin/certutil' '-d' '/tmp/tmpX8lR1Xipa' '-L'
2016-07-12T18:50:22Z DEBUG Process finished, return code=0
2016-07-12T18:50:22Z DEBUG stdout=
Certificate Nickname Trust Attributes
SSL,S/MIME,JAR/XPI
Server-Cert u,u,u
RSINC.LOCAL IPA CA CT,C,C
2016-07-12T18:50:22Z DEBUG stderr=
2016-07-12T18:50:22Z DEBUG importing all plugin modules in ipalib.plugins...
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.aci
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.automember
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.automount
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.baseldap
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.baseuser
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.batch
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.caacl
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.cert
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.certprofile
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.config
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.delegation
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.dns
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.domainlevel
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.group
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.hbacrule
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.hbacsvc
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.hbacsvcgroup
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.hbactest
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.host
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.hostgroup
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.idrange
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.idviews
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.internal
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.kerberos
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.krbtpolicy
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.migration
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.misc
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.netgroup
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.otpconfig
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.otptoken
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.otptoken_yubikey
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.passwd
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.permission
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.ping
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.pkinit
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.privilege
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.pwpolicy
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.radiusproxy
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.realmdomains
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.role
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.rpcclient
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.selfservice
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.selinuxusermap
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.server
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.service
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.servicedelegation
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.session
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.stageuser
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.sudocmd
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.sudocmdgroup
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.sudorule
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.topology
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.trust
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.user
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.vault
2016-07-12T18:50:22Z DEBUG importing plugin module ipalib.plugins.virtual
2016-07-12T18:50:22Z DEBUG importing all plugin modules in ipaserver.plugins...
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.plugins.dogtag
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.plugins.join
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.plugins.ldap2
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.plugins.rabase
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.plugins.xmlserver
2016-07-12T18:50:22Z DEBUG importing all plugin modules in ipaserver.install.plugins...
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.adtrust
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.dns
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.update_nis
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.update_referint
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.update_services
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness
2016-07-12T18:50:22Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt
2016-07-12T18:50:22Z DEBUG SessionAuthManager.register: name=jsonserver_session_90330320
2016-07-12T18:50:22Z DEBUG SessionAuthManager.register: name=xmlserver_session_90332176
2016-07-12T18:50:22Z DEBUG Mounting ipaserver.rpcserver.jsonserver_kerb() at '/json'
2016-07-12T18:50:22Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:22Z DEBUG Mounting ipaserver.rpcserver.xmlserver_session() at '/session/xml'
2016-07-12T18:50:22Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:22Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:22Z DEBUG Mounting ipaserver.rpcserver.sync_token() at '/session/sync_token'
2016-07-12T18:50:22Z DEBUG Mounting ipaserver.rpcserver.xmlserver() at '/xml'
2016-07-12T18:50:22Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:22Z DEBUG Mounting ipaserver.rpcserver.jsonserver_session() at '/session/json'
2016-07-12T18:50:22Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:22Z DEBUG Mounting ipaserver.rpcserver.login_kerberos() at '/session/login_kerberos'
2016-07-12T18:50:22Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:22Z DEBUG Mounting ipaserver.rpcserver.login_password() at '/session/login_password'
2016-07-12T18:50:22Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:50:22Z DEBUG Mounting ipaserver.rpcserver.change_password() at '/session/change_password'
2016-07-12T18:50:24Z DEBUG Created connection context.ldap2_90329936
2016-07-12T18:50:25Z DEBUG raw: domainlevel_get(version=u'2.156')
2016-07-12T18:50:25Z DEBUG domainlevel_get(version=u'2.156')
2016-07-12T18:50:25Z DEBUG flushing ldaps://ipa01-aws.rsinc.local from SchemaCache
2016-07-12T18:50:25Z DEBUG retrieving schema for SchemaCache url=ldaps://ipa01-aws.rsinc.local conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x21ce7a0>
2016-07-12T18:50:29Z DEBUG Check forward/reverse DNS resolution
2016-07-12T18:50:29Z DEBUG Search DNS server ipa01-aws.rsinc.local (['10.10.0.88', '10.10.0.88', '10.10.0.88']) for ipa01-aws.rsinc.local
2016-07-12T18:50:30Z DEBUG Check reverse address 10.10.0.88 (ipa01-aws.rsinc.local)
2016-07-12T18:50:30Z DEBUG Address 10.10.0.88 resolves to: ipa01-aws.rsinc.local..
2016-07-12T18:50:35Z DEBUG Search DNS server ipa01-aws.rsinc.local (['10.10.0.88', '10.10.0.88', '10.10.0.88']) for ipa03-aws.rsinc.local
2016-07-12T18:50:37Z DEBUG Check reverse address 10.40.0.242 (ipa03-aws.rsinc.local)
2016-07-12T18:50:37Z DEBUG Address 10.40.0.242 resolves to: ipa03-aws.rsinc.local..
2016-07-12T18:50:37Z DEBUG Destroyed connection context.ldap2_90329936
2016-07-12T18:50:37Z DEBUG Starting external process
2016-07-12T18:50:37Z DEBUG args='/sbin/ip' '-family' 'inet' '-oneline' 'address' 'show'
2016-07-12T18:50:37Z DEBUG Process finished, return code=0
2016-07-12T18:50:37Z DEBUG stdout=1: lo inet 127.0.0.1/8 scope host lo\ valid_lft forever preferred_lft forever
2: eth0 inet 10.40.0.242/24 brd 10.40.0.255 scope global dynamic eth0\ valid_lft 2160sec preferred_lft 2160sec
2016-07-12T18:50:37Z DEBUG stderr=
2016-07-12T18:50:37Z DEBUG Starting external process
2016-07-12T18:50:37Z DEBUG args='/usr/sbin/ipa-replica-conncheck' '--master' 'ipa01-aws.rsinc.local' '--auto-master-check' '--realm' 'RSINC.LOCAL' '--principal' 'admin' '--hostname' 'ipa03-aws.rsinc.local'
2016-07-12T18:51:19Z DEBUG Process finished, return code=0
2016-07-12T18:51:19Z DEBUG group dirsrv exists
2016-07-12T18:51:19Z DEBUG user dirsrv exists
2016-07-12T18:51:25Z DEBUG Created connection context.ldap2_90329936
2016-07-12T18:51:25Z DEBUG flushing ldaps://ipa01-aws.rsinc.local from SchemaCache
2016-07-12T18:51:25Z DEBUG retrieving schema for SchemaCache url=ldaps://ipa01-aws.rsinc.local conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x5750368>
2016-07-12T18:51:25Z DEBUG Starting external process
2016-07-12T18:51:25Z DEBUG args='/bin/systemctl' 'is-enabled' 'chronyd.service'
2016-07-12T18:51:25Z DEBUG Process finished, return code=0
2016-07-12T18:51:25Z DEBUG stdout=enabled
2016-07-12T18:51:25Z DEBUG stderr=
2016-07-12T18:51:25Z DEBUG Starting external process
2016-07-12T18:51:25Z DEBUG args='/bin/systemctl' 'is-active' 'chronyd.service'
2016-07-12T18:51:25Z DEBUG Process finished, return code=0
2016-07-12T18:51:25Z DEBUG stdout=active
2016-07-12T18:51:25Z DEBUG stderr=
2016-07-12T18:51:25Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:25Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:25Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:25Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:25Z DEBUG Starting external process
2016-07-12T18:51:25Z DEBUG args='/bin/systemctl' 'stop' 'chronyd.service'
2016-07-12T18:51:25Z DEBUG Process finished, return code=0
2016-07-12T18:51:25Z DEBUG stdout=
2016-07-12T18:51:25Z DEBUG stderr=
2016-07-12T18:51:25Z DEBUG Starting external process
2016-07-12T18:51:25Z DEBUG args='/bin/systemctl' 'disable' 'chronyd.service'
2016-07-12T18:51:26Z DEBUG Process finished, return code=0
2016-07-12T18:51:26Z DEBUG stdout=
2016-07-12T18:51:26Z DEBUG stderr=Removed symlink /etc/systemd/system/multi-user.target.wants/chronyd.service.
2016-07-12T18:51:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:26Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:51:26Z DEBUG Configuring NTP daemon (ntpd)
2016-07-12T18:51:26Z DEBUG [1/4]: stopping ntpd
2016-07-12T18:51:26Z DEBUG Starting external process
2016-07-12T18:51:26Z DEBUG args='/bin/systemctl' 'is-active' 'ntpd.service'
2016-07-12T18:51:26Z DEBUG Process finished, return code=3
2016-07-12T18:51:26Z DEBUG stdout=unknown
2016-07-12T18:51:26Z DEBUG stderr=
2016-07-12T18:51:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:26Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:26Z DEBUG Starting external process
2016-07-12T18:51:26Z DEBUG args='/bin/systemctl' 'stop' 'ntpd.service'
2016-07-12T18:51:26Z DEBUG Process finished, return code=0
2016-07-12T18:51:26Z DEBUG stdout=
2016-07-12T18:51:26Z DEBUG stderr=
2016-07-12T18:51:26Z DEBUG duration: 0 seconds
2016-07-12T18:51:26Z DEBUG [2/4]: writing configuration
2016-07-12T18:51:26Z DEBUG Backing up system configuration file '/etc/ntp.conf'
2016-07-12T18:51:26Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:51:26Z DEBUG Backing up system configuration file '/etc/sysconfig/ntpd'
2016-07-12T18:51:26Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:51:26Z DEBUG duration: 0 seconds
2016-07-12T18:51:26Z DEBUG [3/4]: configuring ntpd to start on boot
2016-07-12T18:51:26Z DEBUG Starting external process
2016-07-12T18:51:26Z DEBUG args='/bin/systemctl' 'is-enabled' 'ntpd.service'
2016-07-12T18:51:26Z DEBUG Process finished, return code=1
2016-07-12T18:51:26Z DEBUG stdout=disabled
2016-07-12T18:51:26Z DEBUG stderr=
2016-07-12T18:51:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:26Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:26Z DEBUG Starting external process
2016-07-12T18:51:26Z DEBUG args='/bin/systemctl' 'enable' 'ntpd.service'
2016-07-12T18:51:26Z DEBUG Process finished, return code=0
2016-07-12T18:51:26Z DEBUG stdout=
2016-07-12T18:51:26Z DEBUG stderr=Created symlink from /etc/systemd/system/multi-user.target.wants/ntpd.service to /usr/lib/systemd/system/ntpd.service.
2016-07-12T18:51:26Z DEBUG duration: 0 seconds
2016-07-12T18:51:26Z DEBUG [4/4]: starting ntpd
2016-07-12T18:51:26Z DEBUG Starting external process
2016-07-12T18:51:26Z DEBUG args='/bin/systemctl' 'start' 'ntpd.service'
2016-07-12T18:51:26Z DEBUG Process finished, return code=0
2016-07-12T18:51:26Z DEBUG stdout=
2016-07-12T18:51:26Z DEBUG stderr=
2016-07-12T18:51:26Z DEBUG Starting external process
2016-07-12T18:51:26Z DEBUG args='/bin/systemctl' 'is-active' 'ntpd.service'
2016-07-12T18:51:26Z DEBUG Process finished, return code=0
2016-07-12T18:51:26Z DEBUG stdout=active
2016-07-12T18:51:26Z DEBUG stderr=
2016-07-12T18:51:26Z DEBUG duration: 0 seconds
2016-07-12T18:51:26Z DEBUG Done configuring NTP daemon (ntpd).
2016-07-12T18:51:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:26Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:51:26Z DEBUG Configuring directory server (dirsrv). Estimated time: 1 minute
2016-07-12T18:51:26Z DEBUG [1/38]: creating directory server user
2016-07-12T18:51:26Z DEBUG group dirsrv exists
2016-07-12T18:51:26Z DEBUG user dirsrv exists
2016-07-12T18:51:26Z DEBUG duration: 0 seconds
2016-07-12T18:51:26Z DEBUG [2/38]: creating directory server instance
2016-07-12T18:51:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:26Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:51:26Z DEBUG Backing up system configuration file '/etc/sysconfig/dirsrv'
2016-07-12T18:51:26Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:51:26Z DEBUG
dn: dc=rsinc,dc=local
objectClass: top
objectClass: domain
objectClass: pilotObject
dc: rsinc
info: IPA V2.0
2016-07-12T18:51:26Z DEBUG writing inf template
2016-07-12T18:51:26Z DEBUG
[General]
FullMachineName= ipa03-aws.rsinc.local
SuiteSpotUserID= dirsrv
SuiteSpotGroup= dirsrv
ServerRoot= /usr/lib64/dirsrv
[slapd]
ServerPort= 389
ServerIdentifier= RSINC-LOCAL
Suffix= dc=rsinc,dc=local
RootDN= cn=Directory Manager
InstallLdifFile= /var/lib/dirsrv/boot.ldif
inst_dir= /var/lib/dirsrv/scripts-RSINC-LOCAL
2016-07-12T18:51:26Z DEBUG calling setup-ds.pl
2016-07-12T18:51:26Z DEBUG Starting external process
2016-07-12T18:51:26Z DEBUG args='/usr/sbin/setup-ds.pl' '--silent' '--logfile' '-' '-f' '/tmp/tmpl25s3I'
2016-07-12T18:51:29Z DEBUG Process finished, return code=0
2016-07-12T18:51:29Z DEBUG stdout=[16/07/12:18:51:29] - [Setup] Info Your new DS instance 'RSINC-LOCAL' was successfully created.
Your new DS instance 'RSINC-LOCAL' was successfully created.
[16/07/12:18:51:29] - [Setup] Success Exiting . . .
Log file is '-'
Exiting . . .
Log file is '-'
2016-07-12T18:51:29Z DEBUG stderr=
2016-07-12T18:51:29Z DEBUG completed creating ds instance
2016-07-12T18:51:29Z DEBUG restarting ds instance
2016-07-12T18:51:29Z DEBUG Starting external process
2016-07-12T18:51:29Z DEBUG args='/bin/systemctl' '--system' 'daemon-reload'
2016-07-12T18:51:29Z DEBUG Process finished, return code=0
2016-07-12T18:51:29Z DEBUG stdout=
2016-07-12T18:51:29Z DEBUG stderr=
2016-07-12T18:51:29Z DEBUG Starting external process
2016-07-12T18:51:29Z DEBUG args='/bin/systemctl' 'restart' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:51:31Z DEBUG Process finished, return code=0
2016-07-12T18:51:31Z DEBUG stdout=
2016-07-12T18:51:31Z DEBUG stderr=
2016-07-12T18:51:31Z DEBUG Starting external process
2016-07-12T18:51:31Z DEBUG args='/bin/systemctl' 'is-active' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:51:31Z DEBUG Process finished, return code=0
2016-07-12T18:51:31Z DEBUG stdout=active
2016-07-12T18:51:31Z DEBUG stderr=
2016-07-12T18:51:31Z DEBUG wait_for_open_ports: localhost [389] timeout 300
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/bin/systemctl' 'is-active' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=active
2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG done restarting ds instance
2016-07-12T18:51:32Z DEBUG duration: 6 seconds
2016-07-12T18:51:32Z DEBUG [3/38]: adding default schema
2016-07-12T18:51:32Z DEBUG duration: 0 seconds
2016-07-12T18:51:32Z DEBUG [4/38]: enabling memberof plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/memberof-conf.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpaZTwky'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=replace nsslapd-pluginenabled:
on
add memberofgroupattr:
memberUser
add memberofgroupattr:
memberHost
modifying entry "cn=MemberOf Plugin,cn=plugins,cn=config"
modify complete
2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:32Z DEBUG duration: 0 seconds
2016-07-12T18:51:32Z DEBUG [5/38]: enabling winsync plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/ipa-winsync-conf.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpDGr86O'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectclass:
top
nsSlapdPlugin
extensibleObject
add cn:
ipa-winsync
add nsslapd-pluginpath:
libipa_winsync
add nsslapd-plugininitfunc:
ipa_winsync_plugin_init
add nsslapd-pluginDescription:
Allows IPA to work with the DS windows sync feature
add nsslapd-pluginid:
ipa-winsync
add nsslapd-pluginversion:
1.0
add nsslapd-pluginvendor:
Red Hat
add nsslapd-plugintype:
preoperation
add nsslapd-pluginenabled:
on
add nsslapd-plugin-depends-on-type:
database
add ipaWinSyncRealmFilter:
(objectclass=krbRealmContainer)
add ipaWinSyncRealmAttr:
cn
add ipaWinSyncNewEntryFilter:
(cn=ipaConfig)
add ipaWinSyncNewUserOCAttr:
ipauserobjectclasses
add ipaWinSyncUserFlatten:
true
add ipaWinsyncHomeDirAttr:
ipaHomesRootDir
add ipaWinsyncLoginShellAttr:
ipaDefaultLoginShell
add ipaWinSyncDefaultGroupAttr:
ipaDefaultPrimaryGroup
add ipaWinSyncDefaultGroupFilter:
(gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames)
add ipaWinSyncAcctDisable:
both
add ipaWinSyncForceSync:
true
add ipaWinSyncUserAttr:
uidNumber -1
gidNumber -1
adding new entry "cn=ipa-winsync,cn=plugins,cn=config"
modify complete
2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:32Z DEBUG duration: 0 seconds
2016-07-12T18:51:32Z DEBUG [6/38]: configuring replication version plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/version-conf.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpVufx4k'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectclass:
top
nsSlapdPlugin
extensibleObject
add cn:
IPA Version Replication
add nsslapd-pluginpath:
libipa_repl_version
add nsslapd-plugininitfunc:
repl_version_plugin_init
add nsslapd-plugintype:
preoperation
add nsslapd-pluginenabled:
off
add nsslapd-pluginid:
ipa_repl_version
add nsslapd-pluginversion:
1.0
add nsslapd-pluginvendor:
Red Hat, Inc.
add nsslapd-plugindescription:
IPA Replication version plugin
add nsslapd-plugin-depends-on-type:
database
add nsslapd-plugin-depends-on-named:
Multimaster Replication Plugin
adding new entry "cn=IPA Version Replication,cn=plugins,cn=config"
modify complete
2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:32Z DEBUG duration: 0 seconds
2016-07-12T18:51:32Z DEBUG [7/38]: enabling IPA enrollment plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpvdwlJ_' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmp0DGRqi'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectclass:
top
nsSlapdPlugin
extensibleObject
add cn:
ipa_enrollment_extop
add nsslapd-pluginpath:
libipa_enrollment_extop
add nsslapd-plugininitfunc:
ipaenrollment_init
add nsslapd-plugintype:
extendedop
add nsslapd-pluginenabled:
on
add nsslapd-pluginid:
ipa_enrollment_extop
add nsslapd-pluginversion:
1.0
add nsslapd-pluginvendor:
RedHat
add nsslapd-plugindescription:
Enroll hosts into the IPA domain
add nsslapd-plugin-depends-on-type:
database
add nsslapd-realmTree:
dc=rsinc,dc=local
adding new entry "cn=ipa_enrollment_extop,cn=plugins,cn=config"
modify complete
2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:32Z DEBUG duration: 0 seconds
2016-07-12T18:51:32Z DEBUG [8/38]: enabling ldapi
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpKj0al8' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpgPe4By'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=replace nsslapd-ldapilisten:
on
modifying entry "cn=config"
modify complete
2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:32Z DEBUG duration: 0 seconds
2016-07-12T18:51:32Z DEBUG [9/38]: configuring uniqueness plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpbK4ppH' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmprrUQX8'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectClass:
top
nsSlapdPlugin
extensibleObject
add cn:
krbPrincipalName uniqueness
add nsslapd-pluginPath:
libattr-unique-plugin
add nsslapd-pluginInitfunc:
NSUniqueAttr_Init
add nsslapd-pluginType:
preoperation
add nsslapd-pluginEnabled:
on
add uniqueness-attribute-name:
krbPrincipalName
add nsslapd-plugin-depends-on-type:
database
add nsslapd-pluginId:
NSUniqueAttr
add nsslapd-pluginVersion:
1.1.0
add nsslapd-pluginVendor:
Fedora Project
add nsslapd-pluginDescription:
Enforce unique attribute values
add uniqueness-subtrees:
dc=rsinc,dc=local
add uniqueness-exclude-subtrees:
cn=staged users,cn=accounts,cn=provisioning,dc=rsinc,dc=local
add uniqueness-across-all-subtrees:
on
adding new entry "cn=krbPrincipalName uniqueness,cn=plugins,cn=config"
modify complete
add objectClass:
top
nsSlapdPlugin
extensibleObject
add cn:
krbCanonicalName uniqueness
add nsslapd-pluginPath:
libattr-unique-plugin
add nsslapd-pluginInitfunc:
NSUniqueAttr_Init
add nsslapd-pluginType:
preoperation
add nsslapd-pluginEnabled:
on
add uniqueness-attribute-name:
krbCanonicalName
add nsslapd-plugin-depends-on-type:
database
add nsslapd-pluginId:
NSUniqueAttr
add nsslapd-pluginVersion:
1.1.0
add nsslapd-pluginVendor:
Fedora Project
add nsslapd-pluginDescription:
Enforce unique attribute values
add uniqueness-subtrees:
dc=rsinc,dc=local
add uniqueness-exclude-subtrees:
cn=staged users,cn=accounts,cn=provisioning,dc=rsinc,dc=local
add uniqueness-across-all-subtrees:
on
adding new entry "cn=krbCanonicalName uniqueness,cn=plugins,cn=config"
modify complete
add objectClass:
top
nsSlapdPlugin
extensibleObject
add cn:
netgroup uniqueness
add nsslapd-pluginPath:
libattr-unique-plugin
add nsslapd-pluginInitfunc:
NSUniqueAttr_Init
add nsslapd-pluginType:
preoperation
add nsslapd-pluginEnabled:
on
add uniqueness-attribute-name:
cn
add uniqueness-subtrees:
cn=ng,cn=alt,dc=rsinc,dc=local
add nsslapd-plugin-depends-on-type:
database
add nsslapd-pluginId:
NSUniqueAttr
add nsslapd-pluginVersion:
1.1.0
add nsslapd-pluginVendor:
Fedora Project
add nsslapd-pluginDescription:
Enforce unique attribute values
adding new entry "cn=netgroup uniqueness,cn=plugins,cn=config"
modify complete
add objectClass:
top
nsSlapdPlugin
extensibleObject
add cn:
ipaUniqueID uniqueness
add nsslapd-pluginPath:
libattr-unique-plugin
add nsslapd-pluginInitfunc:
NSUniqueAttr_Init
add nsslapd-pluginType:
preoperation
add nsslapd-pluginEnabled:
on
add uniqueness-attribute-name:
ipaUniqueID
add nsslapd-plugin-depends-on-type:
database
add nsslapd-pluginId:
NSUniqueAttr
add nsslapd-pluginVersion:
1.1.0
add nsslapd-pluginVendor:
Fedora Project
add nsslapd-pluginDescription:
Enforce unique attribute values
add uniqueness-subtrees:
dc=rsinc,dc=local
add uniqueness-exclude-subtrees:
cn=staged users,cn=accounts,cn=provisioning,dc=rsinc,dc=local
add uniqueness-across-all-subtrees:
on
adding new entry "cn=ipaUniqueID uniqueness,cn=plugins,cn=config"
modify complete
add objectClass:
top
nsSlapdPlugin
extensibleObject
add cn:
sudorule name uniqueness
add nsslapd-pluginDescription:
Enforce unique attribute values
add nsslapd-pluginPath:
libattr-unique-plugin
add nsslapd-pluginInitfunc:
NSUniqueAttr_Init
add nsslapd-pluginType:
preoperation
add nsslapd-pluginEnabled:
on
add uniqueness-attribute-name:
cn
add uniqueness-subtrees:
cn=sudorules,cn=sudo,dc=rsinc,dc=local
add nsslapd-plugin-depends-on-type:
database
add nsslapd-pluginId:
NSUniqueAttr
add nsslapd-pluginVersion:
1.1.0
add nsslapd-pluginVendor:
Fedora Project
adding new entry "cn=sudorule name uniqueness,cn=plugins,cn=config"
modify complete
2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:32Z DEBUG duration: 0 seconds
2016-07-12T18:51:32Z DEBUG [10/38]: configuring uuid plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/uuid-conf.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmp5x4unk'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectclass:
top
nsSlapdPlugin
extensibleObject
add cn:
IPA UUID
add nsslapd-pluginpath:
libipa_uuid
add nsslapd-plugininitfunc:
ipauuid_init
add nsslapd-plugintype:
preoperation
add nsslapd-pluginenabled:
on
add nsslapd-pluginid:
ipauuid_version
add nsslapd-pluginversion:
1.0
add nsslapd-pluginvendor:
Red Hat, Inc.
add nsslapd-plugindescription:
IPA UUID plugin
add nsslapd-plugin-depends-on-type:
database
adding new entry "cn=IPA UUID,cn=plugins,cn=config"
modify complete
2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpgvIJlO' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpcigfIB'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectclass:
top
extensibleObject
add cn:
IPA Unique IDs
add ipaUuidAttr:
ipaUniqueID
add ipaUuidMagicRegen:
autogenerate
add ipaUuidFilter:
(|(objectclass=ipaObject)(objectclass=ipaAssociation))
add ipaUuidScope:
dc=rsinc,dc=local
add ipaUuidEnforce:
TRUE
adding new entry "cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config"
modify complete
add objectclass:
top
extensibleObject
add cn:
IPK11 Unique IDs
add ipaUuidAttr:
ipk11UniqueID
add ipaUuidMagicRegen:
autogenerate
add ipaUuidFilter:
(objectclass=ipk11Object)
add ipaUuidScope:
dc=rsinc,dc=local
add ipaUuidEnforce:
FALSE
adding new entry "cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config"
modify complete
2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:32Z DEBUG duration: 0 seconds
2016-07-12T18:51:32Z DEBUG [11/38]: configuring modrdn plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/modrdn-conf.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpL0SCll'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectclass:
top
nsSlapdPlugin
extensibleObject
add cn:
IPA MODRDN
add nsslapd-pluginpath:
libipa_modrdn
add nsslapd-plugininitfunc:
ipamodrdn_init
add nsslapd-plugintype:
betxnpostoperation
add nsslapd-pluginenabled:
on
add nsslapd-pluginid:
ipamodrdn_version
add nsslapd-pluginversion:
1.0
add nsslapd-pluginvendor:
Red Hat, Inc.
add nsslapd-plugindescription:
IPA MODRDN plugin
add nsslapd-plugin-depends-on-type:
database
add nsslapd-pluginPrecedence:
60
adding new entry "cn=IPA MODRDN,cn=plugins,cn=config"
modify complete
2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmp7a9Iy2' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpYqIrA8'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectclass:
top
extensibleObject
add cn:
Kerberos Principal Name
add ipaModRDNsourceAttr:
uid
add ipaModRDNtargetAttr:
krbPrincipalName
add ipaModRDNsuffix:
@RSINC.LOCAL
add ipaModRDNfilter:
(&(objectclass=posixaccount)(objectclass=krbPrincipalAux))
add ipaModRDNscope:
dc=rsinc,dc=local
adding new entry "cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config"
modify complete
2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:32Z DEBUG duration: 0 seconds
2016-07-12T18:51:32Z DEBUG [12/38]: configuring DNS plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/ipa-dns-conf.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpYTbMOB'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectclass:
top
nsslapdPlugin
extensibleObject
add cn:
IPA DNS
add nsslapd-plugindescription:
IPA DNS support plugin
add nsslapd-pluginenabled:
on
add nsslapd-pluginid:
ipa_dns
add nsslapd-plugininitfunc:
ipadns_init
add nsslapd-pluginpath:
libipa_dns.so
add nsslapd-plugintype:
preoperation
add nsslapd-pluginvendor:
Red Hat, Inc.
add nsslapd-pluginversion:
1.0
add nsslapd-plugin-depends-on-type:
database
adding new entry "cn=IPA DNS,cn=plugins,cn=config"
modify complete
2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:32Z DEBUG duration: 0 seconds
2016-07-12T18:51:32Z DEBUG [13/38]: enabling entryUSN plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/entryusn.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpQNVKqh'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=replace nsslapd-entryusn-global:
on
modifying entry "cn=config"
modify complete
replace nsslapd-entryusn-import-initval:
next
modifying entry "cn=config"
modify complete
replace nsslapd-pluginenabled:
on
modifying entry "cn=USN,cn=plugins,cn=config"
modify complete
2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:32Z DEBUG duration: 0 seconds
2016-07-12T18:51:32Z DEBUG [14/38]: configuring lockout plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/lockout-conf.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpuM9MKr'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectclass:
top
nsSlapdPlugin
extensibleObject
add cn:
IPA Lockout
add nsslapd-pluginpath:
libipa_lockout
add nsslapd-plugininitfunc:
ipalockout_init
add nsslapd-plugintype:
object
add nsslapd-pluginenabled:
on
add nsslapd-pluginid:
ipalockout_version
add nsslapd-pluginversion:
1.0
add nsslapd-pluginvendor:
Red Hat, Inc.
add nsslapd-plugindescription:
IPA Lockout plugin
add nsslapd-plugin-depends-on-type:
database
adding new entry "cn=IPA Lockout,cn=plugins,cn=config"
modify complete
2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:32Z DEBUG duration: 0 seconds
2016-07-12T18:51:32Z DEBUG [15/38]: creating indices
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/indices.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmptbeIHR'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=add objectClass:
top
nsIndex
add cn:
krbPrincipalName
add nsSystemIndex:
false
add nsIndexType:
eq
sub
adding new entry "cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add objectClass:
top
nsIndex
add cn:
ou
add nsSystemIndex:
false
add nsIndexType:
eq
sub
adding new entry "cn=ou,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add objectClass:
top
nsIndex
add cn:
carLicense
add nsSystemIndex:
false
add nsIndexType:
eq
sub
adding new entry "cn=carLicense,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add objectClass:
top
nsIndex
add cn:
title
add nsSystemIndex:
false
add nsIndexType:
eq
sub
adding new entry "cn=title,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add objectClass:
top
nsIndex
add cn:
manager
add nsSystemIndex:
false
add nsIndexType:
eq
pres
sub
adding new entry "cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add objectClass:
top
nsIndex
add cn:
secretary
add nsSystemIndex:
false
add nsIndexType:
eq
pres
sub
adding new entry "cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add objectClass:
top
nsIndex
add cn:
displayname
add nsSystemIndex:
false
add nsIndexType:
eq
sub
adding new entry "cn=displayname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add nsIndexType:
sub
modifying entry "cn=uid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add objectClass:
top
nsIndex
add cn:
uidnumber
add nsSystemIndex:
false
add nsIndexType:
eq
add nsMatchingRule:
integerOrderingMatch
adding new entry "cn=uidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add objectClass:
top
nsIndex
add cn:
gidnumber
add nsSystemIndex:
false
add nsIndexType:
eq
add nsMatchingRule:
integerOrderingMatch
adding new entry "cn=gidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
replace nsIndexType:
eq
pres
modifying entry "cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
replace nsIndexType:
eq
pres
modifying entry "cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add ObjectClass:
top
nsIndex
add cn:
fqdn
add nsSystemIndex:
false
add nsIndexType:
eq
pres
adding new entry "cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add ObjectClass:
top
nsIndex
add cn:
macAddress
add nsSystemIndex:
false
add nsIndexType:
eq
pres
adding new entry "cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add cn:
memberHost
add ObjectClass:
top
nsIndex
add nsSystemIndex:
false
add nsIndexType:
eq
pres
sub
adding new entry "cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add cn:
memberUser
add ObjectClass:
top
nsIndex
add nsSystemIndex:
false
add nsIndexType:
eq
pres
sub
adding new entry "cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add cn:
sourcehost
add ObjectClass:
top
nsIndex
add nsSystemIndex:
false
add nsIndexType:
eq
pres
sub
adding new entry "cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add cn:
memberservice
add ObjectClass:
top
nsIndex
add nsSystemIndex:
false
add nsIndexType:
eq
pres
sub
adding new entry "cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add cn:
managedby
add ObjectClass:
top
nsIndex
add nsSystemIndex:
false
add nsIndexType:
eq
pres
sub
adding new entry "cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add cn:
memberallowcmd
add ObjectClass:
top
nsIndex
add nsSystemIndex:
false
add nsIndexType:
eq
pres
sub
adding new entry "cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add cn:
memberdenycmd
add ObjectClass:
top
nsIndex
add nsSystemIndex:
false
add nsIndexType:
eq
pres
sub
adding new entry "cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add cn:
ipasudorunas
add ObjectClass:
top
nsIndex
add nsSystemIndex:
false
add nsIndexType:
eq
pres
sub
adding new entry "cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add cn:
ipasudorunasgroup
add ObjectClass:
top
nsIndex
add nsSystemIndex:
false
add nsIndexType:
eq
pres
sub
adding new entry "cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add cn:
automountkey
add ObjectClass:
top
nsIndex
add nsSystemIndex:
false
add nsIndexType:
eq
adding new entry "cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add cn:
ipakrbprincipalalias
add ObjectClass:
top
nsIndex
add nsSystemIndex:
false
add nsIndexType:
eq
adding new entry "cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add cn:
ipauniqueid
add ObjectClass:
top
nsIndex
add nsSystemIndex:
false
add nsIndexType:
eq
adding new entry "cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add cn:
ipaMemberCa
add ObjectClass:
top
nsIndex
add nsSystemIndex:
false
add nsIndexType:
eq
pres
sub
adding new entry "cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add cn:
ipaMemberCertProfile
add ObjectClass:
top
nsIndex
add nsSystemIndex:
false
add nsIndexType:
eq
pres
sub
adding new entry "cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add cn:
userCertificate
add ObjectClass:
top
nsIndex
add nsSystemIndex:
false
add nsIndexType:
eq
pres
adding new entry "cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:32Z DEBUG duration: 0 seconds
2016-07-12T18:51:32Z DEBUG [16/38]: enabling referential integrity plugin
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/referint-conf.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpQ3LiVG'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=replace nsslapd-pluginenabled:
on
modifying entry "cn=referential integrity postoperation,cn=plugins,cn=config"
modify complete
2016-07-12T18:51:32Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:32Z DEBUG duration: 0 seconds
2016-07-12T18:51:32Z DEBUG [17/38]: configuring ssl for ds instance
2016-07-12T18:51:32Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-N' '-f' '/etc/dirsrv/slapd-RSINC-LOCAL//pwdfile.txt'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=
2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/pk12util' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-i' '/tmp/tmp34bUDTipa/realm_info/dscert.p12' '-k' '/etc/dirsrv/slapd-RSINC-LOCAL//pwdfile.txt' '-v' '-w' '/dev/stdin'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=pk12util: PKCS12 IMPORT SUCCESSFUL
2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-L'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=
Certificate Nickname Trust Attributes
SSL,S/MIME,JAR/XPI
Server-Cert u,u,u
RSINC.LOCAL IPA CA ,,
2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-A' '-n' 'CA 1' '-t' ',,' '-a'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=
2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-O' '-n' 'Server-Cert'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout="RSINC.LOCAL IPA CA" [CN=Certificate Authority,O=RSINC.LOCAL]
"Server-Cert" [CN=ipa03-aws.rsinc.local,O=RSINC.LOCAL]
2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-M' '-n' 'RSINC.LOCAL IPA CA' '-t' 'CT,C,C'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=
2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-O' '-n' 'Server-Cert'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout="RSINC.LOCAL IPA CA" [CN=Certificate Authority,O=RSINC.LOCAL]
"Server-Cert" [CN=ipa03-aws.rsinc.local,O=RSINC.LOCAL]
2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-L' '-n' 'RSINC.LOCAL IPA CA' '-a'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=-----BEGIN CERTIFICATE-----
MIIDkTCCAnmgAwIBAgIBATANBgkqhkiG9w0BAQsFADA2MRQwEgYDVQQKDAtSU0lO
Qy5MT0NBTDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE2MDMx
MTE2NDMxNVoXDTM2MDMxMTE2NDMxNVowNjEUMBIGA1UECgwLUlNJTkMuTE9DQUwx
HjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTCCASIwDQYJKoZIhvcNAQEB
BQADggEPADCCAQoCggEBAMeuq3fFabQUU4lMQmLEQmN4ryu3bp6ekaBc/+4txdYg
AYiSUvZOChcS+6l0XWl/d1u5txR5BIKdADCvO9rcIglQbvn1y6scjbmMqzd4xtCE
IN28t1ywPQlWIAGSLw2VDuZ/lmKxmyG00RMxKRvZYuWe/pHZqiza9Rywyt+hjxDK
GjghSMGujqYiGXuDviR79q+g7WFQP+8e3D59NmGa8N9iGHaVOBYiNBJIS9raDWmY
LvpHY5cBUYrhBGsIIia3l+V2a+9RPXceF7dN5b3xVae5BK2r39ohFtzZw6b1StVS
QLeuAexrabVUZEEltzcSUyZo1pZqfsOfyOA5LUWsIsUCAwEAAaOBqTCBpjAfBgNV
HSMEGDAWgBS7H+9FH63CaSCM3WK2HMFJFSqzUjAPBgNVHRMBAf8EBTADAQH/MA4G
A1UdDwEB/wQEAwIBxjAdBgNVHQ4EFgQUux/vRR+twmkgjN1ithzBSRUqs1IwQwYI
KwYBBQUHAQEENzA1MDMGCCsGAQUFBzABhidodHRwOi8vaXBhMDEtYXdzLnJzaW5j
LmxvY2FsOjgwL2NhL29jc3AwDQYJKoZIhvcNAQELBQADggEBAIuAZ1+x3we31MvO
ZRB3fg3F8JVALb8iZ8EMSktNIlW71A6UwlwMwJi/1yGBuTAp6GwgZTKETBJ40hqx
1G7DSXaViXmIf8ERRvM/0LEba+Skokt9N+F+kQeOE340/YEMvUR/uiGaaEurA3dm
WsoJ0z/X401qHLH7XIyTKubI+TK6unVFwO+p6OUb/n+/ZTBPY5CluwsH67qHxAFf
WBsn6fd+2kl10LC6Z/drQ+yPbApn8wo0k1Pvht2w01nFji9z3C6zsk7JG+EJ0l8W
LqXaFqEeRJlG+aPmadqEYDWBE8A05+5euoc8z/zLJXZLWSMs4PpKwcuWlWZ+84gV
N2jzdNA=
-----END CERTIFICATE-----
2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-L'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=
Certificate Nickname Trust Attributes
SSL,S/MIME,JAR/XPI
Server-Cert u,u,u
RSINC.LOCAL IPA CA CT,C,C
2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-L' '-n' 'Server-Cert' '-a'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=-----BEGIN CERTIFICATE-----
MIIEEzCCAvugAwIBAgIBOzANBgkqhkiG9w0BAQsFADA2MRQwEgYDVQQKDAtSU0lO
Qy5MT0NBTDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE2MDcx
MjE4NDczMloXDTE4MDcxMzE4NDczMlowNjEUMBIGA1UECgwLUlNJTkMuTE9DQUwx
HjAcBgNVBAMMFWlwYTAzLWF3cy5yc2luYy5sb2NhbDCCASIwDQYJKoZIhvcNAQEB
BQADggEPADCCAQoCggEBAL71KZYz8sy6erF5VJH0HrZuzikcrEl/4y8MdqzV8NQ2
yRZDlDzLqcj5hs+RafbKFFQyksP1eO5YkeTllATMetFD8vqqFVIpunlr/u8dbTlM
/vlKOZJ0wvlPjc5QeuGtFVZ/z5vqQKKtFHrFziglx8yMAH1C6R4afFhyMqnQigzT
WHWdc3BLQy2xVyadt0oode1PnWu2diwwV3wEbtja4TA9e8lPKdMWHKIpd2l9+iso
iXP+IvuTLJkMwXKEFjUEgNFetPEbOf+EzXtd6iU7BGKxDplxyvkOf3sG5psR1LJa
Hd3Cp1DHf06XceqvzQbIbVPoL0qk560tz0rch30/Ek8CAwEAAaOCASowggEmMB8G
A1UdIwQYMBaAFLsf70UfrcJpIIzdYrYcwUkVKrNSMD0GCCsGAQUFBwEBBDEwLzAt
BggrBgEFBQcwAYYhaHR0cDovL2lwYS1jYS5yc2luYy5sb2NhbC9jYS9vY3NwMA4G
A1UdDwEB/wQEAwIE8DAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwdgYD
VR0fBG8wbTBroDOgMYYvaHR0cDovL2lwYS1jYS5yc2luYy5sb2NhbC9pcGEvY3Js
L01hc3RlckNSTC5iaW6iNKQyMDAxDjAMBgNVBAoMBWlwYWNhMR4wHAYDVQQDDBVD
ZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHQYDVR0OBBYEFLkqG3ftJkzasSZs+3Xrbu/0
967tMA0GCSqGSIb3DQEBCwUAA4IBAQC6C+6HRuRVotLiS6A1dV/5UQmVohfcIg6P
bI7KSpDSLvcVJvA0rxr2QGfUvpgqa4I62mfxe7tefqs+QLwGLUpdG4OYGmOkiDzi
PUuj7BFI9qRVqGrfH+pcsorY5Zz7Z2JjY3v0TSiPImUIw/s4R6izHT7iUCOhVBPf
ZOeGRKbCihWygPeoz/0m0+P3AIT3U6MV/819Y3woLvyJC/OImkZZVI2HcfU/07Yh
TsHUZsavZX4xfwk6pdKYwg4yw5KGUCWL/WR1QPdEr/QDQeo75jQmaS3fIBxQpCva
2YPxLYfcIdP30GCl9dEg4SE3b19L+6Nuv0rbMai4WtPNr6U/jjWM
-----END CERTIFICATE-----
2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:32Z DEBUG Starting external process
2016-07-12T18:51:32Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-L' '-n' 'Server-Cert' '-a'
2016-07-12T18:51:32Z DEBUG Process finished, return code=0
2016-07-12T18:51:32Z DEBUG stdout=-----BEGIN CERTIFICATE-----
MIIEEzCCAvugAwIBAgIBOzANBgkqhkiG9w0BAQsFADA2MRQwEgYDVQQKDAtSU0lO
Qy5MT0NBTDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE2MDcx
MjE4NDczMloXDTE4MDcxMzE4NDczMlowNjEUMBIGA1UECgwLUlNJTkMuTE9DQUwx
HjAcBgNVBAMMFWlwYTAzLWF3cy5yc2luYy5sb2NhbDCCASIwDQYJKoZIhvcNAQEB
BQADggEPADCCAQoCggEBAL71KZYz8sy6erF5VJH0HrZuzikcrEl/4y8MdqzV8NQ2
yRZDlDzLqcj5hs+RafbKFFQyksP1eO5YkeTllATMetFD8vqqFVIpunlr/u8dbTlM
/vlKOZJ0wvlPjc5QeuGtFVZ/z5vqQKKtFHrFziglx8yMAH1C6R4afFhyMqnQigzT
WHWdc3BLQy2xVyadt0oode1PnWu2diwwV3wEbtja4TA9e8lPKdMWHKIpd2l9+iso
iXP+IvuTLJkMwXKEFjUEgNFetPEbOf+EzXtd6iU7BGKxDplxyvkOf3sG5psR1LJa
Hd3Cp1DHf06XceqvzQbIbVPoL0qk560tz0rch30/Ek8CAwEAAaOCASowggEmMB8G
A1UdIwQYMBaAFLsf70UfrcJpIIzdYrYcwUkVKrNSMD0GCCsGAQUFBwEBBDEwLzAt
BggrBgEFBQcwAYYhaHR0cDovL2lwYS1jYS5yc2luYy5sb2NhbC9jYS9vY3NwMA4G
A1UdDwEB/wQEAwIE8DAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwdgYD
VR0fBG8wbTBroDOgMYYvaHR0cDovL2lwYS1jYS5yc2luYy5sb2NhbC9pcGEvY3Js
L01hc3RlckNSTC5iaW6iNKQyMDAxDjAMBgNVBAoMBWlwYWNhMR4wHAYDVQQDDBVD
ZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHQYDVR0OBBYEFLkqG3ftJkzasSZs+3Xrbu/0
967tMA0GCSqGSIb3DQEBCwUAA4IBAQC6C+6HRuRVotLiS6A1dV/5UQmVohfcIg6P
bI7KSpDSLvcVJvA0rxr2QGfUvpgqa4I62mfxe7tefqs+QLwGLUpdG4OYGmOkiDzi
PUuj7BFI9qRVqGrfH+pcsorY5Zz7Z2JjY3v0TSiPImUIw/s4R6izHT7iUCOhVBPf
ZOeGRKbCihWygPeoz/0m0+P3AIT3U6MV/819Y3woLvyJC/OImkZZVI2HcfU/07Yh
TsHUZsavZX4xfwk6pdKYwg4yw5KGUCWL/WR1QPdEr/QDQeo75jQmaS3fIBxQpCva
2YPxLYfcIdP30GCl9dEg4SE3b19L+6Nuv0rbMai4WtPNr6U/jjWM
-----END CERTIFICATE-----
2016-07-12T18:51:32Z DEBUG stderr=
2016-07-12T18:51:33Z DEBUG flushing ldap://ipa03-aws.rsinc.local:389 from SchemaCache
2016-07-12T18:51:33Z DEBUG retrieving schema for SchemaCache url=ldap://ipa03-aws.rsinc.local:389 conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x7aad638>
2016-07-12T18:51:33Z DEBUG duration: 0 seconds
2016-07-12T18:51:33Z DEBUG [18/38]: configuring certmap.conf
2016-07-12T18:51:33Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state'
2016-07-12T18:51:33Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state'
2016-07-12T18:51:33Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state'
2016-07-12T18:51:33Z DEBUG duration: 0 seconds
2016-07-12T18:51:33Z DEBUG [19/38]: configure autobind for root
2016-07-12T18:51:33Z DEBUG Starting external process
2016-07-12T18:51:33Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/root-autobind.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmp6rzPZX'
2016-07-12T18:51:33Z DEBUG Process finished, return code=0
2016-07-12T18:51:33Z DEBUG stdout=add objectClass:
extensibleObject
top
add cn:
root-autobind
add uidNumber:
0
add gidNumber:
0
adding new entry "cn=root-autobind,cn=config"
modify complete
replace nsslapd-ldapiautobind:
on
modifying entry "cn=config"
modify complete
replace nsslapd-ldapimaptoentries:
on
modifying entry "cn=config"
modify complete
2016-07-12T18:51:33Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:33Z DEBUG duration: 0 seconds
2016-07-12T18:51:33Z DEBUG [20/38]: configure new location for managed entries
2016-07-12T18:51:33Z DEBUG Starting external process
2016-07-12T18:51:33Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpcTTK6a' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpA3Dzpt'
2016-07-12T18:51:33Z DEBUG Process finished, return code=0
2016-07-12T18:51:33Z DEBUG stdout=add nsslapd-pluginConfigArea:
cn=Definitions,cn=Managed Entries,cn=etc,dc=rsinc,dc=local
modifying entry "cn=Managed Entries,cn=plugins,cn=config"
modify complete
2016-07-12T18:51:33Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:33Z DEBUG duration: 0 seconds
2016-07-12T18:51:33Z DEBUG [21/38]: configure dirsrv ccache
2016-07-12T18:51:33Z DEBUG Backing up system configuration file '/etc/sysconfig/dirsrv'
2016-07-12T18:51:33Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:51:33Z DEBUG Starting external process
2016-07-12T18:51:33Z DEBUG args='/usr/sbin/selinuxenabled'
2016-07-12T18:51:33Z DEBUG Process finished, return code=0
2016-07-12T18:51:33Z DEBUG stdout=
2016-07-12T18:51:33Z DEBUG stderr=
2016-07-12T18:51:33Z DEBUG Starting external process
2016-07-12T18:51:33Z DEBUG args='/sbin/restorecon' '/etc/sysconfig/dirsrv'
2016-07-12T18:51:33Z DEBUG Process finished, return code=0
2016-07-12T18:51:33Z DEBUG stdout=
2016-07-12T18:51:33Z DEBUG stderr=
2016-07-12T18:51:33Z DEBUG duration: 0 seconds
2016-07-12T18:51:33Z DEBUG [22/38]: enable SASL mapping fallback
2016-07-12T18:51:33Z DEBUG Starting external process
2016-07-12T18:51:33Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpiDf5XR' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpU_gcYB'
2016-07-12T18:51:33Z DEBUG Process finished, return code=0
2016-07-12T18:51:33Z DEBUG stdout=replace nsslapd-sasl-mapping-fallback:
on
modifying entry "cn=config"
modify complete
2016-07-12T18:51:33Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:33Z DEBUG duration: 0 seconds
2016-07-12T18:51:33Z DEBUG [23/38]: restarting directory server
2016-07-12T18:51:33Z DEBUG Starting external process
2016-07-12T18:51:33Z DEBUG args='/bin/systemctl' '--system' 'daemon-reload'
2016-07-12T18:51:33Z DEBUG Process finished, return code=0
2016-07-12T18:51:33Z DEBUG stdout=
2016-07-12T18:51:33Z DEBUG stderr=
2016-07-12T18:51:33Z DEBUG Starting external process
2016-07-12T18:51:33Z DEBUG args='/bin/systemctl' 'restart' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:51:34Z DEBUG Process finished, return code=0
2016-07-12T18:51:34Z DEBUG stdout=
2016-07-12T18:51:34Z DEBUG stderr=
2016-07-12T18:51:34Z DEBUG Starting external process
2016-07-12T18:51:34Z DEBUG args='/bin/systemctl' 'is-active' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:51:34Z DEBUG Process finished, return code=0
2016-07-12T18:51:34Z DEBUG stdout=active
2016-07-12T18:51:34Z DEBUG stderr=
2016-07-12T18:51:34Z DEBUG wait_for_open_ports: localhost [389] timeout 300
2016-07-12T18:51:35Z DEBUG Starting external process
2016-07-12T18:51:35Z DEBUG args='/bin/systemctl' 'is-active' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:51:35Z DEBUG Process finished, return code=0
2016-07-12T18:51:35Z DEBUG stdout=active
2016-07-12T18:51:35Z DEBUG stderr=
2016-07-12T18:51:35Z DEBUG duration: 2 seconds
2016-07-12T18:51:35Z DEBUG [24/38]: setting up initial replication
2016-07-12T18:51:35Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-RSINC-LOCAL.socket from SchemaCache
2016-07-12T18:51:35Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-RSINC-LOCAL.socket conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x7a96680>
2016-07-12T18:51:35Z DEBUG Starting external process
2016-07-12T18:51:35Z DEBUG args='/bin/systemctl' '--system' 'daemon-reload'
2016-07-12T18:51:35Z DEBUG Process finished, return code=0
2016-07-12T18:51:35Z DEBUG stdout=
2016-07-12T18:51:35Z DEBUG stderr=
2016-07-12T18:51:35Z DEBUG Starting external process
2016-07-12T18:51:35Z DEBUG args='/bin/systemctl' 'restart' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:51:36Z DEBUG Process finished, return code=0
2016-07-12T18:51:36Z DEBUG stdout=
2016-07-12T18:51:36Z DEBUG stderr=
2016-07-12T18:51:36Z DEBUG Starting external process
2016-07-12T18:51:36Z DEBUG args='/bin/systemctl' 'is-active' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:51:36Z DEBUG Process finished, return code=0
2016-07-12T18:51:36Z DEBUG stdout=active
2016-07-12T18:51:36Z DEBUG stderr=
2016-07-12T18:51:36Z DEBUG wait_for_open_ports: localhost [389] timeout 300
2016-07-12T18:51:38Z DEBUG Fetching nsDS5ReplicaId from master [attempt 1/5]
2016-07-12T18:51:38Z DEBUG flushing ldap://ipa01-aws.rsinc.local:389 from SchemaCache
2016-07-12T18:51:38Z DEBUG retrieving schema for SchemaCache url=ldap://ipa01-aws.rsinc.local:389 conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x81dd758>
2016-07-12T18:51:39Z DEBUG Successfully updated nsDS5ReplicaId.
2016-07-12T18:51:39Z DEBUG flushing ldaps://ipa03-aws.rsinc.local:636 from SchemaCache
2016-07-12T18:51:39Z DEBUG retrieving schema for SchemaCache url=ldaps://ipa03-aws.rsinc.local:636 conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x81dd8c0>
2016-07-12T18:51:49Z DEBUG duration: 14 seconds
2016-07-12T18:51:49Z DEBUG [25/38]: updating schema
2016-07-12T18:51:49Z DEBUG Starting external process
2016-07-12T18:51:49Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/usr/share/ipa/schema-update.ldif' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpWvrmTP'
2016-07-12T18:51:50Z DEBUG Process finished, return code=0
2016-07-12T18:51:50Z DEBUG stdout=add objectClasses:
( 2.16.840.1.113730.3.2.41 NAME 'nsslapdPlugin' DESC 'Netscape defined objectclass' SUP top MUST ( cn $ nsslapd-pluginPath $ nsslapd-pluginInitFunc $ nsslapd-pluginType $ nsslapd-pluginId $ nsslapd-pluginVersion $ nsslapd-pluginVendor $ nsslapd-pluginDescription $ nsslapd-pluginEnabled ) MAY ( nsslapd-pluginConfigArea $ nsslapd-plugin-depends-on-type ) X-ORIGIN 'Netscape Directory Server' )
( 2.16.840.1.113730.3.2.317 NAME 'nsSaslMapping' DESC 'Netscape defined objectclass' SUP top MUST ( cn $ nsSaslMapRegexString $ nsSaslMapBaseDNTemplate $ nsSaslMapFilterTemplate ) MAY ( nsSaslMapPriority ) X-ORIGIN 'Netscape Directory Server' )
modifying entry "cn=schema"
modify complete
2016-07-12T18:51:50Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:50Z DEBUG duration: 0 seconds
2016-07-12T18:51:50Z DEBUG [26/38]: setting Auto Member configuration
2016-07-12T18:51:50Z DEBUG Starting external process
2016-07-12T18:51:50Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmp1eCPZ_' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpVqf5cB'
2016-07-12T18:51:50Z DEBUG Process finished, return code=0
2016-07-12T18:51:50Z DEBUG stdout=add nsslapd-pluginConfigArea:
cn=automember,cn=etc,dc=rsinc,dc=local
modifying entry "cn=Auto Membership Plugin,cn=plugins,cn=config"
modify complete
2016-07-12T18:51:50Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:50Z DEBUG duration: 0 seconds
2016-07-12T18:51:50Z DEBUG [27/38]: enabling S4U2Proxy delegation
2016-07-12T18:51:50Z DEBUG Starting external process
2016-07-12T18:51:50Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpY17efF' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmp8IK3SH'
2016-07-12T18:51:50Z DEBUG Process finished, return code=0
2016-07-12T18:51:50Z DEBUG stdout=add memberPrincipal:
HTTP/ipa03-aws.rsinc.local at RSINC.LOCAL
modifying entry "cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=rsinc,dc=local"
modify complete
add memberPrincipal:
ldap/ipa03-aws.rsinc.local at RSINC.LOCAL
modifying entry "cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=rsinc,dc=local"
modify complete
2016-07-12T18:51:50Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:50Z DEBUG duration: 0 seconds
2016-07-12T18:51:50Z DEBUG [28/38]: importing CA certificates from LDAP
2016-07-12T18:51:50Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:51:50Z DEBUG flushing ldap://ipa03-aws.rsinc.local:389 from SchemaCache
2016-07-12T18:51:50Z DEBUG retrieving schema for SchemaCache url=ldap://ipa03-aws.rsinc.local:389 conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x7c80cf8>
2016-07-12T18:51:50Z DEBUG Starting external process
2016-07-12T18:51:50Z DEBUG args='/usr/bin/certutil' '-d' '/etc/dirsrv/slapd-RSINC-LOCAL/' '-A' '-n' 'RSINC.LOCAL IPA CA' '-t' 'CT,C,C'
2016-07-12T18:51:50Z DEBUG Process finished, return code=0
2016-07-12T18:51:50Z DEBUG stdout=
2016-07-12T18:51:50Z DEBUG stderr=
2016-07-12T18:51:50Z DEBUG duration: 0 seconds
2016-07-12T18:51:50Z DEBUG [29/38]: initializing group membership
2016-07-12T18:51:50Z DEBUG duration: 0 seconds
2016-07-12T18:51:50Z DEBUG [30/38]: adding master entry
2016-07-12T18:51:50Z DEBUG Starting external process
2016-07-12T18:51:50Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpxaLDRH' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpm2TMAE'
2016-07-12T18:51:50Z DEBUG Process finished, return code=0
2016-07-12T18:51:50Z DEBUG stdout=add objectclass:
top
nsContainer
ipaReplTopoManagedServer
ipaConfigObject
ipaSupportedDomainLevelConfig
add cn:
ipa03-aws.rsinc.local
add ipaReplTopoManagedSuffix:
dc=rsinc,dc=local
add ipaMinDomainLevel:
0
add ipaMaxDomainLevel:
0
adding new entry "cn=ipa03-aws.rsinc.local,cn=masters,cn=ipa,cn=etc,dc=rsinc,dc=local"
modify complete
2016-07-12T18:51:50Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:50Z DEBUG duration: 0 seconds
2016-07-12T18:51:50Z DEBUG [31/38]: initializing domain level
2016-07-12T18:51:50Z DEBUG duration: 0 seconds
2016-07-12T18:51:50Z DEBUG [32/38]: configuring Posix uid/gid generation
2016-07-12T18:51:50Z DEBUG Starting external process
2016-07-12T18:51:50Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpIYMDRE' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmp2EyXWe'
2016-07-12T18:51:50Z DEBUG Process finished, return code=0
2016-07-12T18:51:50Z DEBUG stdout=add objectclass:
top
extensibleObject
add cn:
Posix IDs
add dnaType:
uidNumber
gidNumber
add dnaNextValue:
1101
add dnaMaxValue:
1100
add dnaMagicRegen:
-1
add dnaFilter:
(|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject))
add dnaScope:
dc=rsinc,dc=local
add dnaThreshold:
500
add dnaSharedCfgDN:
cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=rsinc,dc=local
adding new entry "cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config"
modify complete
2016-07-12T18:51:50Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:50Z DEBUG duration: 0 seconds
2016-07-12T18:51:50Z DEBUG [33/38]: adding replication acis
2016-07-12T18:51:50Z DEBUG Starting external process
2016-07-12T18:51:50Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpfjnnUg' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmporl0Uz'
2016-07-12T18:51:50Z DEBUG Process finished, return code=0
2016-07-12T18:51:50Z DEBUG stdout=add aci:
(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=rsinc,dc=local";)
modifying entry "cn="dc=rsinc,dc=local",cn=mapping tree,cn=config"
modify complete
add aci:
(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=rsinc,dc=local";)
modifying entry "cn="dc=rsinc,dc=local",cn=mapping tree,cn=config"
modify complete
add aci:
(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=rsinc,dc=local";)
modifying entry "cn="dc=rsinc,dc=local",cn=mapping tree,cn=config"
modify complete
add aci:
(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=rsinc,dc=local";)
modifying entry "cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config"
modify complete
add aci:
(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=rsinc,dc=local";)
modifying entry "cn=userRoot,cn=ldbm database,cn=plugins,cn=config"
modify complete
add aci:
(targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=rsinc,dc=local";)
modifying entry "cn=tasks,cn=config"
modify complete
2016-07-12T18:51:50Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:50Z DEBUG duration: 0 seconds
2016-07-12T18:51:50Z DEBUG [34/38]: enabling compatibility plugin
2016-07-12T18:51:50Z DEBUG importing all plugin modules in ipalib.plugins...
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.aci
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.automember
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.automount
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.baseldap
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.baseuser
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.batch
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.caacl
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.cert
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.certprofile
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.config
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.delegation
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.dns
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.domainlevel
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.group
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.hbacrule
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.hbacsvc
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.hbacsvcgroup
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.hbactest
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.host
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.hostgroup
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.idrange
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.idviews
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.internal
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.kerberos
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.krbtpolicy
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.migration
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.misc
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.netgroup
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.otpconfig
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.otptoken
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.otptoken_yubikey
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.passwd
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.permission
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.ping
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.pkinit
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.privilege
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.pwpolicy
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.radiusproxy
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.realmdomains
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.role
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.rpcclient
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.selfservice
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.selinuxusermap
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.server
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.service
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.servicedelegation
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.session
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.stageuser
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.sudocmd
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.sudocmdgroup
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.sudorule
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.topology
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.trust
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.user
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.vault
2016-07-12T18:51:50Z DEBUG importing plugin module ipalib.plugins.virtual
2016-07-12T18:51:50Z DEBUG importing all plugin modules in ipaserver.plugins...
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.plugins.dogtag
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.plugins.join
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.plugins.ldap2
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.plugins.rabase
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.plugins.xmlserver
2016-07-12T18:51:50Z DEBUG importing all plugin modules in ipaserver.install.plugins...
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.adtrust
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.dns
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.update_nis
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.update_referint
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.update_services
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness
2016-07-12T18:51:50Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt
2016-07-12T18:51:50Z DEBUG SessionAuthManager.register: name=jsonserver_session_146012624
2016-07-12T18:51:50Z DEBUG SessionAuthManager.register: name=xmlserver_session_146030864
2016-07-12T18:51:51Z DEBUG Mounting ipaserver.rpcserver.jsonserver_kerb() at '/json'
2016-07-12T18:51:51Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:51:51Z DEBUG Mounting ipaserver.rpcserver.xmlserver_session() at '/session/xml'
2016-07-12T18:51:51Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:51:51Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:51:51Z DEBUG Mounting ipaserver.rpcserver.sync_token() at '/session/sync_token'
2016-07-12T18:51:51Z DEBUG Mounting ipaserver.rpcserver.xmlserver() at '/xml'
2016-07-12T18:51:51Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:51:51Z DEBUG Mounting ipaserver.rpcserver.jsonserver_session() at '/session/json'
2016-07-12T18:51:51Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:51:51Z DEBUG Mounting ipaserver.rpcserver.login_kerberos() at '/session/login_kerberos'
2016-07-12T18:51:51Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:51:51Z DEBUG Mounting ipaserver.rpcserver.login_password() at '/session/login_password'
2016-07-12T18:51:51Z DEBUG session_auth_duration: 0:20:00
2016-07-12T18:51:51Z DEBUG Mounting ipaserver.rpcserver.change_password() at '/session/change_password'
2016-07-12T18:51:52Z DEBUG Created connection context.ldap2_146012240
2016-07-12T18:51:52Z DEBUG Destroyed connection context.ldap2_146012240
2016-07-12T18:51:52Z DEBUG Created connection context.ldap2_146012240
2016-07-12T18:51:52Z DEBUG Parsing update file '/usr/share/ipa/schema_compat.uldif'
2016-07-12T18:51:52Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-RSINC-LOCAL.socket from SchemaCache
2016-07-12T18:51:52Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-RSINC-LOCAL.socket conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x264dc68>
2016-07-12T18:51:52Z DEBUG New entry: cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Initial value
2016-07-12T18:51:52Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG nsslapd-pluginid:
2016-07-12T18:51:52Z DEBUG schema-compat-plugin
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG Schema Compatibility
2016-07-12T18:51:52Z DEBUG nsslapd-pluginbetxn:
2016-07-12T18:51:52Z DEBUG on
2016-07-12T18:51:52Z DEBUG objectclass:
2016-07-12T18:51:52Z DEBUG top
2016-07-12T18:51:52Z DEBUG nsSlapdPlugin
2016-07-12T18:51:52Z DEBUG extensibleObject
2016-07-12T18:51:52Z DEBUG nsslapd-plugindescription:
2016-07-12T18:51:52Z DEBUG Schema Compatibility Plugin
2016-07-12T18:51:52Z DEBUG nsslapd-pluginenabled:
2016-07-12T18:51:52Z DEBUG on
2016-07-12T18:51:52Z DEBUG nsslapd-pluginpath:
2016-07-12T18:51:52Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so
2016-07-12T18:51:52Z DEBUG nsslapd-pluginversion:
2016-07-12T18:51:52Z DEBUG 0.8
2016-07-12T18:51:52Z DEBUG nsslapd-pluginvendor:
2016-07-12T18:51:52Z DEBUG redhat.com
2016-07-12T18:51:52Z DEBUG nsslapd-pluginprecedence:
2016-07-12T18:51:52Z DEBUG 49
2016-07-12T18:51:52Z DEBUG nsslapd-plugintype:
2016-07-12T18:51:52Z DEBUG object
2016-07-12T18:51:52Z DEBUG nsslapd-plugininitfunc:
2016-07-12T18:51:52Z DEBUG schema_compat_plugin_init
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Final value after applying updates
2016-07-12T18:51:52Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG nsslapd-pluginid:
2016-07-12T18:51:52Z DEBUG schema-compat-plugin
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG Schema Compatibility
2016-07-12T18:51:52Z DEBUG nsslapd-pluginbetxn:
2016-07-12T18:51:52Z DEBUG on
2016-07-12T18:51:52Z DEBUG objectclass:
2016-07-12T18:51:52Z DEBUG top
2016-07-12T18:51:52Z DEBUG nsSlapdPlugin
2016-07-12T18:51:52Z DEBUG extensibleObject
2016-07-12T18:51:52Z DEBUG nsslapd-plugindescription:
2016-07-12T18:51:52Z DEBUG Schema Compatibility Plugin
2016-07-12T18:51:52Z DEBUG nsslapd-pluginenabled:
2016-07-12T18:51:52Z DEBUG on
2016-07-12T18:51:52Z DEBUG nsslapd-pluginpath:
2016-07-12T18:51:52Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so
2016-07-12T18:51:52Z DEBUG nsslapd-pluginversion:
2016-07-12T18:51:52Z DEBUG 0.8
2016-07-12T18:51:52Z DEBUG nsslapd-pluginvendor:
2016-07-12T18:51:52Z DEBUG redhat.com
2016-07-12T18:51:52Z DEBUG nsslapd-pluginprecedence:
2016-07-12T18:51:52Z DEBUG 49
2016-07-12T18:51:52Z DEBUG nsslapd-plugintype:
2016-07-12T18:51:52Z DEBUG object
2016-07-12T18:51:52Z DEBUG nsslapd-plugininitfunc:
2016-07-12T18:51:52Z DEBUG schema_compat_plugin_init
2016-07-12T18:51:52Z DEBUG New entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Initial value
2016-07-12T18:51:52Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG schema-compat-entry-attribute:
2016-07-12T18:51:52Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")
2016-07-12T18:51:52Z DEBUG cn=%{cn}
2016-07-12T18:51:52Z DEBUG objectclass=posixAccount
2016-07-12T18:51:52Z DEBUG gidNumber=%{gidNumber}
2016-07-12T18:51:52Z DEBUG gecos=%{cn}
2016-07-12T18:51:52Z DEBUG ipaanchoruuid=%{ipaanchoruuid}
2016-07-12T18:51:52Z DEBUG uidNumber=%{uidNumber}
2016-07-12T18:51:52Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:rsinc.local:%{ipauniqueid}","")
2016-07-12T18:51:52Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")
2016-07-12T18:51:52Z DEBUG loginShell=%{loginShell}
2016-07-12T18:51:52Z DEBUG homeDirectory=%{homeDirectory}
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG users
2016-07-12T18:51:52Z DEBUG objectClass:
2016-07-12T18:51:52Z DEBUG top
2016-07-12T18:51:52Z DEBUG extensibleObject
2016-07-12T18:51:52Z DEBUG schema-compat-search-filter:
2016-07-12T18:51:52Z DEBUG objectclass=posixAccount
2016-07-12T18:51:52Z DEBUG schema-compat-container-rdn:
2016-07-12T18:51:52Z DEBUG cn=users
2016-07-12T18:51:52Z DEBUG schema-compat-entry-rdn:
2016-07-12T18:51:52Z DEBUG uid=%{uid}
2016-07-12T18:51:52Z DEBUG schema-compat-search-base:
2016-07-12T18:51:52Z DEBUG cn=users, cn=accounts, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG schema-compat-container-group:
2016-07-12T18:51:52Z DEBUG cn=compat, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Final value after applying updates
2016-07-12T18:51:52Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG schema-compat-entry-attribute:
2016-07-12T18:51:52Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")
2016-07-12T18:51:52Z DEBUG cn=%{cn}
2016-07-12T18:51:52Z DEBUG objectclass=posixAccount
2016-07-12T18:51:52Z DEBUG gidNumber=%{gidNumber}
2016-07-12T18:51:52Z DEBUG gecos=%{cn}
2016-07-12T18:51:52Z DEBUG ipaanchoruuid=%{ipaanchoruuid}
2016-07-12T18:51:52Z DEBUG uidNumber=%{uidNumber}
2016-07-12T18:51:52Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:rsinc.local:%{ipauniqueid}","")
2016-07-12T18:51:52Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")
2016-07-12T18:51:52Z DEBUG loginShell=%{loginShell}
2016-07-12T18:51:52Z DEBUG homeDirectory=%{homeDirectory}
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG users
2016-07-12T18:51:52Z DEBUG objectClass:
2016-07-12T18:51:52Z DEBUG top
2016-07-12T18:51:52Z DEBUG extensibleObject
2016-07-12T18:51:52Z DEBUG schema-compat-search-filter:
2016-07-12T18:51:52Z DEBUG objectclass=posixAccount
2016-07-12T18:51:52Z DEBUG schema-compat-container-rdn:
2016-07-12T18:51:52Z DEBUG cn=users
2016-07-12T18:51:52Z DEBUG schema-compat-entry-rdn:
2016-07-12T18:51:52Z DEBUG uid=%{uid}
2016-07-12T18:51:52Z DEBUG schema-compat-search-base:
2016-07-12T18:51:52Z DEBUG cn=users, cn=accounts, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG schema-compat-container-group:
2016-07-12T18:51:52Z DEBUG cn=compat, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG New entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Initial value
2016-07-12T18:51:52Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG schema-compat-entry-attribute:
2016-07-12T18:51:52Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")
2016-07-12T18:51:52Z DEBUG ipaanchoruuid=%{ipaanchoruuid}
2016-07-12T18:51:52Z DEBUG gidNumber=%{gidNumber}
2016-07-12T18:51:52Z DEBUG objectclass=posixGroup
2016-07-12T18:51:52Z DEBUG memberUid=%{memberUid}
2016-07-12T18:51:52Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:rsinc.local:%{ipauniqueid}","")
2016-07-12T18:51:52Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")
2016-07-12T18:51:52Z DEBUG memberUid=%deref_r("member","uid")
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG groups
2016-07-12T18:51:52Z DEBUG objectClass:
2016-07-12T18:51:52Z DEBUG top
2016-07-12T18:51:52Z DEBUG extensibleObject
2016-07-12T18:51:52Z DEBUG schema-compat-search-filter:
2016-07-12T18:51:52Z DEBUG objectclass=posixGroup
2016-07-12T18:51:52Z DEBUG schema-compat-container-rdn:
2016-07-12T18:51:52Z DEBUG cn=groups
2016-07-12T18:51:52Z DEBUG schema-compat-entry-rdn:
2016-07-12T18:51:52Z DEBUG cn=%{cn}
2016-07-12T18:51:52Z DEBUG schema-compat-search-base:
2016-07-12T18:51:52Z DEBUG cn=groups, cn=accounts, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG schema-compat-container-group:
2016-07-12T18:51:52Z DEBUG cn=compat, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Final value after applying updates
2016-07-12T18:51:52Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG schema-compat-entry-attribute:
2016-07-12T18:51:52Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")
2016-07-12T18:51:52Z DEBUG ipaanchoruuid=%{ipaanchoruuid}
2016-07-12T18:51:52Z DEBUG gidNumber=%{gidNumber}
2016-07-12T18:51:52Z DEBUG objectclass=posixGroup
2016-07-12T18:51:52Z DEBUG memberUid=%{memberUid}
2016-07-12T18:51:52Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:rsinc.local:%{ipauniqueid}","")
2016-07-12T18:51:52Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")
2016-07-12T18:51:52Z DEBUG memberUid=%deref_r("member","uid")
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG groups
2016-07-12T18:51:52Z DEBUG objectClass:
2016-07-12T18:51:52Z DEBUG top
2016-07-12T18:51:52Z DEBUG extensibleObject
2016-07-12T18:51:52Z DEBUG schema-compat-search-filter:
2016-07-12T18:51:52Z DEBUG objectclass=posixGroup
2016-07-12T18:51:52Z DEBUG schema-compat-container-rdn:
2016-07-12T18:51:52Z DEBUG cn=groups
2016-07-12T18:51:52Z DEBUG schema-compat-entry-rdn:
2016-07-12T18:51:52Z DEBUG cn=%{cn}
2016-07-12T18:51:52Z DEBUG schema-compat-search-base:
2016-07-12T18:51:52Z DEBUG cn=groups, cn=accounts, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG schema-compat-container-group:
2016-07-12T18:51:52Z DEBUG cn=compat, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG New entry: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Initial value
2016-07-12T18:51:52Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG add: 'top' to objectClass, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['top']
2016-07-12T18:51:52Z DEBUG add: 'extensibleObject' to objectClass, current value ['top']
2016-07-12T18:51:52Z DEBUG add: updated value ['top', 'extensibleObject']
2016-07-12T18:51:52Z DEBUG add: 'ng' to cn, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['ng']
2016-07-12T18:51:52Z DEBUG add: 'cn=compat, dc=rsinc,dc=local' to schema-compat-container-group, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['cn=compat, dc=rsinc,dc=local']
2016-07-12T18:51:52Z DEBUG add: 'cn=ng' to schema-compat-container-rdn, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['cn=ng']
2016-07-12T18:51:52Z DEBUG add: 'yes' to schema-compat-check-access, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['yes']
2016-07-12T18:51:52Z DEBUG add: 'cn=ng, cn=alt, dc=rsinc,dc=local' to schema-compat-search-base, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['cn=ng, cn=alt, dc=rsinc,dc=local']
2016-07-12T18:51:52Z DEBUG add: '(objectclass=ipaNisNetgroup)' to schema-compat-search-filter, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['(objectclass=ipaNisNetgroup)']
2016-07-12T18:51:52Z DEBUG add: 'cn=%{cn}' to schema-compat-entry-rdn, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['cn=%{cn}']
2016-07-12T18:51:52Z DEBUG add: 'objectclass=nisNetgroup' to schema-compat-entry-attribute, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['objectclass=nisNetgroup']
2016-07-12T18:51:52Z DEBUG add: 'memberNisNetgroup=%deref_r("member","cn")' to schema-compat-entry-attribute, current value ['objectclass=nisNetgroup']
2016-07-12T18:51:52Z DEBUG add: updated value ['objectclass=nisNetgroup', 'memberNisNetgroup=%deref_r("member","cn")']
2016-07-12T18:51:52Z DEBUG add: 'nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-})' to schema-compat-entry-attribute, current value ['memberNisNetgroup=%deref_r("member","cn")', 'objectclass=nisNetgroup']
2016-07-12T18:51:52Z DEBUG add: updated value ['memberNisNetgroup=%deref_r("member","cn")', 'objectclass=nisNetgroup', 'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","-",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","-"),%{nisDomainName:-})']
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Final value after applying updates
2016-07-12T18:51:52Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG schema-compat-entry-attribute:
2016-07-12T18:51:52Z DEBUG memberNisNetgroup=%deref_r("member","cn")
2016-07-12T18:51:52Z DEBUG objectclass=nisNetgroup
2016-07-12T18:51:52Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-})
2016-07-12T18:51:52Z DEBUG schema-compat-check-access:
2016-07-12T18:51:52Z DEBUG yes
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG ng
2016-07-12T18:51:52Z DEBUG objectClass:
2016-07-12T18:51:52Z DEBUG top
2016-07-12T18:51:52Z DEBUG extensibleObject
2016-07-12T18:51:52Z DEBUG schema-compat-search-filter:
2016-07-12T18:51:52Z DEBUG (objectclass=ipaNisNetgroup)
2016-07-12T18:51:52Z DEBUG schema-compat-container-rdn:
2016-07-12T18:51:52Z DEBUG cn=ng
2016-07-12T18:51:52Z DEBUG schema-compat-entry-rdn:
2016-07-12T18:51:52Z DEBUG cn=%{cn}
2016-07-12T18:51:52Z DEBUG schema-compat-search-base:
2016-07-12T18:51:52Z DEBUG cn=ng, cn=alt, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG schema-compat-container-group:
2016-07-12T18:51:52Z DEBUG cn=compat, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG New entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Initial value
2016-07-12T18:51:52Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG add: 'top' to objectClass, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['top']
2016-07-12T18:51:52Z DEBUG add: 'extensibleObject' to objectClass, current value ['top']
2016-07-12T18:51:52Z DEBUG add: updated value ['top', 'extensibleObject']
2016-07-12T18:51:52Z DEBUG add: 'sudoers' to cn, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoers']
2016-07-12T18:51:52Z DEBUG add: 'ou=SUDOers, dc=rsinc,dc=local' to schema-compat-container-group, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['ou=SUDOers, dc=rsinc,dc=local']
2016-07-12T18:51:52Z DEBUG add: 'cn=sudorules, cn=sudo, dc=rsinc,dc=local' to schema-compat-search-base, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['cn=sudorules, cn=sudo, dc=rsinc,dc=local']
2016-07-12T18:51:52Z DEBUG add: '(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))' to schema-compat-search-filter, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))']
2016-07-12T18:51:52Z DEBUG add: '%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")' to schema-compat-entry-rdn, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")']
2016-07-12T18:51:52Z DEBUG add: 'objectclass=sudoRole' to schema-compat-entry-attribute, current value []
2016-07-12T18:51:52Z DEBUG add: updated value ['objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")']
2016-07-12T18:51:52Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")']
2016-07-12T18:51:52Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")']
2016-07-12T18:51:52Z DEBUG add: 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")']
2016-07-12T18:51:52Z DEBUG add: 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")']
2016-07-12T18:51:52Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")']
2016-07-12T18:51:52Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")']
2016-07-12T18:51:52Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'objectclass=sudoRole', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")']
2016-07-12T18:51:52Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")']
2016-07-12T18:51:52Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")']
2016-07-12T18:51:52Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")']
2016-07-12T18:51:52Z DEBUG add: 'sudoOption=%{ipaSudoOpt}' to schema-compat-entry-attribute, current value ['sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")']
2016-07-12T18:51:52Z DEBUG add: updated value ['sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}']
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Final value after applying updates
2016-07-12T18:51:52Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG schema-compat-entry-attribute:
2016-07-12T18:51:52Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")
2016-07-12T18:51:52Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")
2016-07-12T18:51:52Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")")
2016-07-12T18:51:52Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")")
2016-07-12T18:51:52Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")")
2016-07-12T18:51:52Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")
2016-07-12T18:51:52Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")")
2016-07-12T18:51:52Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")
2016-07-12T18:51:52Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")")
2016-07-12T18:51:52Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")")
2016-07-12T18:51:52Z DEBUG objectclass=sudoRole
2016-07-12T18:51:52Z DEBUG sudoOption=%{ipaSudoOpt}
2016-07-12T18:51:52Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")")
2016-07-12T18:51:52Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")")
2016-07-12T18:51:52Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")
2016-07-12T18:51:52Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")")
2016-07-12T18:51:52Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")
2016-07-12T18:51:52Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")")
2016-07-12T18:51:52Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")
2016-07-12T18:51:52Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd")
2016-07-12T18:51:52Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")
2016-07-12T18:51:52Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")")
2016-07-12T18:51:52Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG sudoers
2016-07-12T18:51:52Z DEBUG objectClass:
2016-07-12T18:51:52Z DEBUG top
2016-07-12T18:51:52Z DEBUG extensibleObject
2016-07-12T18:51:52Z DEBUG schema-compat-search-filter:
2016-07-12T18:51:52Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))
2016-07-12T18:51:52Z DEBUG schema-compat-entry-rdn:
2016-07-12T18:51:52Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")
2016-07-12T18:51:52Z DEBUG schema-compat-search-base:
2016-07-12T18:51:52Z DEBUG cn=sudorules, cn=sudo, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG schema-compat-container-group:
2016-07-12T18:51:52Z DEBUG ou=SUDOers, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG New entry: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Initial value
2016-07-12T18:51:52Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG schema-compat-entry-attribute:
2016-07-12T18:51:52Z DEBUG objectclass=device
2016-07-12T18:51:52Z DEBUG cn=%{fqdn}
2016-07-12T18:51:52Z DEBUG macAddress=%{macAddress}
2016-07-12T18:51:52Z DEBUG objectclass=ieee802Device
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG computers
2016-07-12T18:51:52Z DEBUG objectClass:
2016-07-12T18:51:52Z DEBUG top
2016-07-12T18:51:52Z DEBUG extensibleObject
2016-07-12T18:51:52Z DEBUG schema-compat-search-filter:
2016-07-12T18:51:52Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost))
2016-07-12T18:51:52Z DEBUG schema-compat-container-rdn:
2016-07-12T18:51:52Z DEBUG cn=computers
2016-07-12T18:51:52Z DEBUG schema-compat-entry-rdn:
2016-07-12T18:51:52Z DEBUG cn=%first("%{fqdn}")
2016-07-12T18:51:52Z DEBUG schema-compat-search-base:
2016-07-12T18:51:52Z DEBUG cn=computers, cn=accounts, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG schema-compat-container-group:
2016-07-12T18:51:52Z DEBUG cn=compat, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Final value after applying updates
2016-07-12T18:51:52Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config
2016-07-12T18:51:52Z DEBUG schema-compat-entry-attribute:
2016-07-12T18:51:52Z DEBUG objectclass=device
2016-07-12T18:51:52Z DEBUG cn=%{fqdn}
2016-07-12T18:51:52Z DEBUG macAddress=%{macAddress}
2016-07-12T18:51:52Z DEBUG objectclass=ieee802Device
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG computers
2016-07-12T18:51:52Z DEBUG objectClass:
2016-07-12T18:51:52Z DEBUG top
2016-07-12T18:51:52Z DEBUG extensibleObject
2016-07-12T18:51:52Z DEBUG schema-compat-search-filter:
2016-07-12T18:51:52Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost))
2016-07-12T18:51:52Z DEBUG schema-compat-container-rdn:
2016-07-12T18:51:52Z DEBUG cn=computers
2016-07-12T18:51:52Z DEBUG schema-compat-entry-rdn:
2016-07-12T18:51:52Z DEBUG cn=%first("%{fqdn}")
2016-07-12T18:51:52Z DEBUG schema-compat-search-base:
2016-07-12T18:51:52Z DEBUG cn=computers, cn=accounts, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG schema-compat-container-group:
2016-07-12T18:51:52Z DEBUG cn=compat, dc=rsinc,dc=local
2016-07-12T18:51:52Z DEBUG Updating existing entry: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Initial value
2016-07-12T18:51:52Z DEBUG dn: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config
2016-07-12T18:51:52Z DEBUG objectClass:
2016-07-12T18:51:52Z DEBUG top
2016-07-12T18:51:52Z DEBUG directoryServerFeature
2016-07-12T18:51:52Z DEBUG aci:
2016-07-12T18:51:52Z DEBUG (targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";)
2016-07-12T18:51:52Z DEBUG oid:
2016-07-12T18:51:52Z DEBUG 2.16.840.1.113730.3.4.9
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG VLV Request Control
2016-07-12T18:51:52Z DEBUG only: set aci to '(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )', current value ['(targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";)']
2016-07-12T18:51:52Z DEBUG only: updated value ['(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )']
2016-07-12T18:51:52Z DEBUG ---------------------------------------------
2016-07-12T18:51:52Z DEBUG Final value after applying updates
2016-07-12T18:51:52Z DEBUG dn: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config
2016-07-12T18:51:52Z DEBUG objectClass:
2016-07-12T18:51:52Z DEBUG top
2016-07-12T18:51:52Z DEBUG directoryServerFeature
2016-07-12T18:51:52Z DEBUG aci:
2016-07-12T18:51:52Z DEBUG (targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )
2016-07-12T18:51:52Z DEBUG oid:
2016-07-12T18:51:52Z DEBUG 2.16.840.1.113730.3.4.9
2016-07-12T18:51:52Z DEBUG cn:
2016-07-12T18:51:52Z DEBUG VLV Request Control
2016-07-12T18:51:52Z DEBUG [(0, u'aci', ['(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )']), (1, u'aci', ['(targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";)'])]
2016-07-12T18:51:52Z DEBUG Updated 1
2016-07-12T18:51:52Z DEBUG Done
2016-07-12T18:51:52Z DEBUG Destroyed connection context.ldap2_146012240
2016-07-12T18:51:52Z DEBUG duration: 1 seconds
2016-07-12T18:51:52Z DEBUG [35/38]: activating sidgen plugin
2016-07-12T18:51:52Z DEBUG Starting external process
2016-07-12T18:51:52Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpHNifK0' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpu7gGVO'
2016-07-12T18:51:52Z DEBUG Process finished, return code=0
2016-07-12T18:51:52Z DEBUG stdout=add objectclass:
top
nsSlapdPlugin
extensibleObject
add cn:
IPA SIDGEN
add nsslapd-pluginpath:
libipa_sidgen
add nsslapd-plugininitfunc:
ipa_sidgen_init
add nsslapd-plugintype:
postoperation
add nsslapd-pluginenabled:
on
add nsslapd-pluginid:
ipa_sidgen_postop
add nsslapd-pluginversion:
1.0
add nsslapd-pluginvendor:
Red Hat, Inc.
add nsslapd-plugindescription:
IPA SIDGEN post operation
add nsslapd-plugin-depends-on-type:
database
add nsslapd-basedn:
dc=rsinc,dc=local
adding new entry "cn=IPA SIDGEN,cn=plugins,cn=config"
modify complete
2016-07-12T18:51:52Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:52Z DEBUG duration: 0 seconds
2016-07-12T18:51:52Z DEBUG [36/38]: activating extdom plugin
2016-07-12T18:51:52Z DEBUG Starting external process
2016-07-12T18:51:52Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpIyfltw' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpk7JxMO'
2016-07-12T18:51:52Z DEBUG Process finished, return code=0
2016-07-12T18:51:52Z DEBUG stdout=add objectclass:
top
nsSlapdPlugin
extensibleObject
add cn:
ipa_extdom_extop
add nsslapd-pluginpath:
libipa_extdom_extop
add nsslapd-plugininitfunc:
ipa_extdom_init
add nsslapd-plugintype:
extendedop
add nsslapd-pluginenabled:
on
add nsslapd-pluginid:
ipa_extdom_extop
add nsslapd-pluginversion:
1.0
add nsslapd-pluginvendor:
RedHat
add nsslapd-plugindescription:
Support resolving IDs in trusted domains to names and back
add nsslapd-plugin-depends-on-type:
database
add nsslapd-basedn:
dc=rsinc,dc=local
adding new entry "cn=ipa_extdom_extop,cn=plugins,cn=config"
modify complete
2016-07-12T18:51:52Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:51:52Z DEBUG duration: 0 seconds
2016-07-12T18:51:52Z DEBUG [37/38]: tuning directory server
2016-07-12T18:51:52Z DEBUG Starting external process
2016-07-12T18:51:52Z DEBUG args='/usr/sbin/selinuxenabled'
2016-07-12T18:51:52Z DEBUG Process finished, return code=0
2016-07-12T18:51:52Z DEBUG stdout=
2016-07-12T18:51:52Z DEBUG stderr=
2016-07-12T18:51:52Z DEBUG Starting external process
2016-07-12T18:51:52Z DEBUG args='/sbin/restorecon' '/etc/sysconfig/dirsrv.systemd'
2016-07-12T18:51:52Z DEBUG Process finished, return code=0
2016-07-12T18:51:52Z DEBUG stdout=
2016-07-12T18:51:52Z DEBUG stderr=
2016-07-12T18:51:52Z DEBUG Starting external process
2016-07-12T18:51:52Z DEBUG args='/bin/systemctl' '--system' 'daemon-reload'
2016-07-12T18:51:52Z DEBUG Process finished, return code=0
2016-07-12T18:51:52Z DEBUG stdout=
2016-07-12T18:51:52Z DEBUG stderr=
2016-07-12T18:51:52Z DEBUG Starting external process
2016-07-12T18:51:52Z DEBUG args='/bin/systemctl' '--system' 'daemon-reload'
2016-07-12T18:51:52Z DEBUG Process finished, return code=0
2016-07-12T18:51:52Z DEBUG stdout=
2016-07-12T18:51:52Z DEBUG stderr=
2016-07-12T18:51:52Z DEBUG Starting external process
2016-07-12T18:51:52Z DEBUG args='/bin/systemctl' 'restart' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:52:01Z DEBUG Process finished, return code=0
2016-07-12T18:52:01Z DEBUG stdout=
2016-07-12T18:52:01Z DEBUG stderr=
2016-07-12T18:52:01Z DEBUG Starting external process
2016-07-12T18:52:01Z DEBUG args='/bin/systemctl' 'is-active' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:52:01Z DEBUG Process finished, return code=0
2016-07-12T18:52:01Z DEBUG stdout=active
2016-07-12T18:52:01Z DEBUG stderr=
2016-07-12T18:52:01Z DEBUG wait_for_open_ports: localhost [389] timeout 300
2016-07-12T18:52:02Z DEBUG Starting external process
2016-07-12T18:52:02Z DEBUG args='/bin/systemctl' 'is-active' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:52:02Z DEBUG Process finished, return code=0
2016-07-12T18:52:02Z DEBUG stdout=active
2016-07-12T18:52:02Z DEBUG stderr=
2016-07-12T18:52:02Z DEBUG Starting external process
2016-07-12T18:52:02Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpBnJ9Ee' '-H' 'ldap://ipa03-aws.rsinc.local:389' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpYQYFCf'
2016-07-12T18:52:02Z DEBUG Process finished, return code=0
2016-07-12T18:52:02Z DEBUG stdout=replace nsslapd-maxdescriptors:
8192
replace nsslapd-reservedescriptors:
64
modifying entry "cn=config"
modify complete
2016-07-12T18:52:02Z DEBUG stderr=ldap_initialize( ldap://ipa03-aws.rsinc.local:389/??base )
2016-07-12T18:52:02Z DEBUG duration: 10 seconds
2016-07-12T18:52:02Z DEBUG [38/38]: configuring directory to start on boot
2016-07-12T18:52:02Z DEBUG Starting external process
2016-07-12T18:52:02Z DEBUG args='/bin/systemctl' 'is-enabled' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:52:02Z DEBUG Process finished, return code=0
2016-07-12T18:52:02Z DEBUG stdout=enabled
2016-07-12T18:52:02Z DEBUG stderr=
2016-07-12T18:52:02Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:02Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:02Z DEBUG Starting external process
2016-07-12T18:52:02Z DEBUG args='/bin/systemctl' 'disable' 'dirsrv at RSINC-LOCAL.service'
2016-07-12T18:52:02Z DEBUG Process finished, return code=0
2016-07-12T18:52:02Z DEBUG stdout=
2016-07-12T18:52:02Z DEBUG stderr=Removed symlink /etc/systemd/system/dirsrv.target.wants/dirsrv at RSINC-LOCAL.service.
2016-07-12T18:52:02Z DEBUG duration: 0 seconds
2016-07-12T18:52:02Z DEBUG Done configuring directory server (dirsrv).
2016-07-12T18:52:03Z DEBUG flushing ldaps://ipa01-aws.rsinc.local:636 from SchemaCache
2016-07-12T18:52:03Z DEBUG retrieving schema for SchemaCache url=ldaps://ipa01-aws.rsinc.local:636 conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x81dfcb0>
2016-07-12T18:52:04Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:04Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:52:04Z DEBUG raw: dnszone_show(u'242.0.40.10.in-addr.arpa.', version=u'2.156')
2016-07-12T18:52:04Z DEBUG dnszone_show(<DNS name 242.0.40.10.in-addr.arpa.>, rights=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:04Z DEBUG raw: dnszone_show(u'0.40.10.in-addr.arpa.', version=u'2.156')
2016-07-12T18:52:04Z DEBUG dnszone_show(<DNS name 0.40.10.in-addr.arpa.>, rights=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:04Z DEBUG raw: dnsrecord_add(u'rsinc.local', u'_ldap._tcp', srvrecord=u'0 100 389 ipa03-aws', version=u'2.156')
2016-07-12T18:52:04Z DEBUG dnsrecord_add(<DNS name rsinc.local.>, <DNS name _ldap._tcp>, a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=(u'0 100 389 ipa03-aws',), force=False, structured=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:06Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:06Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:06Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:06Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:06Z DEBUG raw: dnsrecord_add(u'rsinc.local', u'_kerberos._tcp', srvrecord=u'0 100 88 ipa03-aws', version=u'2.156')
2016-07-12T18:52:06Z DEBUG dnsrecord_add(<DNS name rsinc.local.>, <DNS name _kerberos._tcp>, a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=(u'0 100 88 ipa03-aws',), force=False, structured=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:07Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:07Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:07Z DEBUG raw: dnsrecord_add(u'rsinc.local', u'_kerberos._udp', srvrecord=u'0 100 88 ipa03-aws', version=u'2.156')
2016-07-12T18:52:07Z DEBUG dnsrecord_add(<DNS name rsinc.local.>, <DNS name _kerberos._udp>, a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=(u'0 100 88 ipa03-aws',), force=False, structured=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:08Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:08Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:08Z DEBUG raw: dnsrecord_add(u'rsinc.local', u'_kerberos-master._tcp', srvrecord=u'0 100 88 ipa03-aws', version=u'2.156')
2016-07-12T18:52:08Z DEBUG dnsrecord_add(<DNS name rsinc.local.>, <DNS name _kerberos-master._tcp>, a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=(u'0 100 88 ipa03-aws',), force=False, structured=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:09Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:09Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:09Z DEBUG raw: dnsrecord_add(u'rsinc.local', u'_kerberos-master._udp', srvrecord=u'0 100 88 ipa03-aws', version=u'2.156')
2016-07-12T18:52:09Z DEBUG dnsrecord_add(<DNS name rsinc.local.>, <DNS name _kerberos-master._udp>, a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=(u'0 100 88 ipa03-aws',), force=False, structured=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:10Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:10Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:10Z DEBUG raw: dnsrecord_add(u'rsinc.local', u'_kpasswd._tcp', srvrecord=u'0 100 464 ipa03-aws', version=u'2.156')
2016-07-12T18:52:10Z DEBUG dnsrecord_add(<DNS name rsinc.local.>, <DNS name _kpasswd._tcp>, a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=(u'0 100 464 ipa03-aws',), force=False, structured=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:11Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:11Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:11Z DEBUG raw: dnsrecord_add(u'rsinc.local', u'_kpasswd._udp', srvrecord=u'0 100 464 ipa03-aws', version=u'2.156')
2016-07-12T18:52:11Z DEBUG dnsrecord_add(<DNS name rsinc.local.>, <DNS name _kpasswd._udp>, a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=(u'0 100 464 ipa03-aws',), force=False, structured=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:12Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:12Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:12Z DEBUG raw: dnsrecord_add(u'rsinc.local', u'_ntp._udp', srvrecord=u'0 100 123 ipa03-aws', version=u'2.156')
2016-07-12T18:52:12Z DEBUG dnsrecord_add(<DNS name rsinc.local.>, <DNS name _ntp._udp>, a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=(u'0 100 123 ipa03-aws',), force=False, structured=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:15Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:15Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:15Z DEBUG raw: dnszone_show(u'rsinc.local', version=u'2.156')
2016-07-12T18:52:15Z DEBUG dnszone_show(<DNS name rsinc.local.>, rights=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:15Z DEBUG raw: dnsrecord_add(u'rsinc.local', u'ipa03-aws', arecord=u'1', version=u'2.156')
2016-07-12T18:52:15Z DEBUG dnsrecord_add(<DNS name rsinc.local.>, <DNS name ipa03-aws>, arecord=(u'1',), a_extra_create_reverse=False, aaaa_extra_create_reverse=False, force=False, structured=False, all=False, raw=False, version=u'2.156')
2016-07-12T18:52:15Z INFO Replica DNS records could not be added on master: invalid 'ip_address': Gettext('invalid IP address format', domain='ipa', localedir=None)
2016-07-12T18:52:15Z DEBUG Destroyed connection context.ldap2_90329936
2016-07-12T18:52:15Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:15Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:52:15Z DEBUG Starting external process
2016-07-12T18:52:15Z DEBUG args='keyctl' 'get_persistent' '@s' '0'
2016-07-12T18:52:15Z DEBUG Process finished, return code=0
2016-07-12T18:52:15Z DEBUG stdout=173686621
2016-07-12T18:52:15Z DEBUG stderr=
2016-07-12T18:52:15Z DEBUG Enabling persistent keyring CCACHE
2016-07-12T18:52:15Z DEBUG Starting external process
2016-07-12T18:52:15Z DEBUG args='/bin/systemctl' 'is-active' 'krb5kdc.service'
2016-07-12T18:52:15Z DEBUG Process finished, return code=3
2016-07-12T18:52:15Z DEBUG stdout=unknown
2016-07-12T18:52:15Z DEBUG stderr=
2016-07-12T18:52:15Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:15Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'
2016-07-12T18:52:15Z DEBUG Starting external process
2016-07-12T18:52:15Z DEBUG args='/bin/systemctl' 'stop' 'krb5kdc.service'
2016-07-12T18:52:15Z DEBUG Process finished, return code=0
2016-07-12T18:52:15Z DEBUG stdout=
2016-07-12T18:52:15Z DEBUG stderr=
2016-07-12T18:52:15Z DEBUG Configuring Kerberos KDC (krb5kdc). Estimated time: 30 seconds
2016-07-12T18:52:15Z DEBUG [1/8]: adding sasl mappings to the directory
2016-07-12T18:52:15Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-RSINC-LOCAL.socket from SchemaCache
2016-07-12T18:52:15Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-RSINC-LOCAL.socket conn=<ldap.ldapobject.SimpleLDAPObject instance at 0xaa60ab8>
2016-07-12T18:52:16Z DEBUG duration: 1 seconds
2016-07-12T18:52:16Z DEBUG [2/8]: configuring KDC
2016-07-12T18:52:16Z DEBUG Backing up system configuration file '/var/kerberos/krb5kdc/kdc.conf'
2016-07-12T18:52:16Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:52:16Z DEBUG Backing up system configuration file '/etc/krb5.conf'
2016-07-12T18:52:16Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:52:16Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krb5.ini'
2016-07-12T18:52:16Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:52:16Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krb.con'
2016-07-12T18:52:16Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:52:16Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krbrealm.con'
2016-07-12T18:52:16Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:52:16Z DEBUG Starting external process
2016-07-12T18:52:16Z DEBUG args='klist' '-V'
2016-07-12T18:52:16Z DEBUG Process finished, return code=0
2016-07-12T18:52:16Z DEBUG stdout=Kerberos 5 version 1.13.2
2016-07-12T18:52:16Z DEBUG stderr=
2016-07-12T18:52:16Z DEBUG Backing up system configuration file '/etc/sysconfig/krb5kdc'
2016-07-12T18:52:16Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:52:16Z DEBUG Starting external process
2016-07-12T18:52:16Z DEBUG args='/usr/sbin/selinuxenabled'
2016-07-12T18:52:16Z DEBUG Process finished, return code=0
2016-07-12T18:52:16Z DEBUG stdout=
2016-07-12T18:52:16Z DEBUG stderr=
2016-07-12T18:52:16Z DEBUG Starting external process
2016-07-12T18:52:16Z DEBUG args='/sbin/restorecon' '/etc/sysconfig/krb5kdc'
2016-07-12T18:52:16Z DEBUG Process finished, return code=0
2016-07-12T18:52:16Z DEBUG stdout=
2016-07-12T18:52:16Z DEBUG stderr=
2016-07-12T18:52:16Z DEBUG duration: 0 seconds
2016-07-12T18:52:16Z DEBUG [3/8]: creating a keytab for the directory
2016-07-12T18:52:16Z DEBUG Starting external process
2016-07-12T18:52:16Z DEBUG args='kadmin.local' '-q' 'addprinc -randkey ldap/ipa03-aws.rsinc.local at RSINC.LOCAL' '-x' 'ipa-setup-override-restrictions'
2016-07-12T18:52:16Z DEBUG Process finished, return code=0
2016-07-12T18:52:16Z DEBUG stdout=Authenticating as principal root/admin at RSINC.LOCAL with password.
Principal "ldap/ipa03-aws.rsinc.local at RSINC.LOCAL" created.
2016-07-12T18:52:16Z DEBUG stderr=WARNING: no policy specified for ldap/ipa03-aws.rsinc.local at RSINC.LOCAL; defaulting to no policy
2016-07-12T18:52:17Z DEBUG Backing up system configuration file '/etc/dirsrv/ds.keytab'
2016-07-12T18:52:17Z DEBUG -> Not backing up - '/etc/dirsrv/ds.keytab' doesn't exist
2016-07-12T18:52:17Z DEBUG Starting external process
2016-07-12T18:52:17Z DEBUG args='kadmin.local' '-q' 'ktadd -k /etc/dirsrv/ds.keytab ldap/ipa03-aws.rsinc.local at RSINC.LOCAL' '-x' 'ipa-setup-override-restrictions'
2016-07-12T18:52:17Z DEBUG Process finished, return code=0
2016-07-12T18:52:17Z DEBUG stdout=Authenticating as principal root/admin at RSINC.LOCAL with password.
Entry for principal ldap/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/dirsrv/ds.keytab.
Entry for principal ldap/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/dirsrv/ds.keytab.
Entry for principal ldap/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type des3-cbc-sha1 added to keytab WRFILE:/etc/dirsrv/ds.keytab.
Entry for principal ldap/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type arcfour-hmac added to keytab WRFILE:/etc/dirsrv/ds.keytab.
Entry for principal ldap/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/dirsrv/ds.keytab.
Entry for principal ldap/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/dirsrv/ds.keytab.
2016-07-12T18:52:17Z DEBUG stderr=
2016-07-12T18:52:17Z DEBUG duration: 0 seconds
2016-07-12T18:52:17Z DEBUG [4/8]: creating a keytab for the machine
2016-07-12T18:52:17Z DEBUG Starting external process
2016-07-12T18:52:17Z DEBUG args='kadmin.local' '-q' 'addprinc -randkey host/ipa03-aws.rsinc.local at RSINC.LOCAL' '-x' 'ipa-setup-override-restrictions'
2016-07-12T18:52:17Z DEBUG Process finished, return code=0
2016-07-12T18:52:17Z DEBUG stdout=Authenticating as principal root/admin at RSINC.LOCAL with password.
Principal "host/ipa03-aws.rsinc.local at RSINC.LOCAL" created.
2016-07-12T18:52:17Z DEBUG stderr=WARNING: no policy specified for host/ipa03-aws.rsinc.local at RSINC.LOCAL; defaulting to no policy
2016-07-12T18:52:17Z DEBUG Backing up system configuration file '/etc/krb5.keytab'
2016-07-12T18:52:17Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'
2016-07-12T18:52:17Z DEBUG Starting external process
2016-07-12T18:52:17Z DEBUG args='kadmin.local' '-q' 'ktadd -k /etc/krb5.keytab host/ipa03-aws.rsinc.local at RSINC.LOCAL' '-x' 'ipa-setup-override-restrictions'
2016-07-12T18:52:17Z DEBUG Process finished, return code=0
2016-07-12T18:52:17Z DEBUG stdout=Authenticating as principal root/admin at RSINC.LOCAL with password.
Entry for principal host/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/krb5.keytab.
Entry for principal host/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/krb5.keytab.
Entry for principal host/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type des3-cbc-sha1 added to keytab WRFILE:/etc/krb5.keytab.
Entry for principal host/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type arcfour-hmac added to keytab WRFILE:/etc/krb5.keytab.
Entry for principal host/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/krb5.keytab.
Entry for principal host/ipa03-aws.rsinc.local at RSINC.LOCAL with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/krb5.keytab.
2016-07-12T18:52:17Z DEBUG stderr=
2016-07-12T18:52:17Z DEBUG duration: 0 seconds
2016-07-12T18:52:17Z DEBUG [5/8]: adding the password extension to the directory
2016-07-12T18:52:17Z DEBUG Starting external process
2016-07-12T18:52:17Z DEBUG args='/usr/bin/ldapmodify' '-v' '-f' '/tmp/tmpsCS1tk' '-H' 'ldapi://%2fvar%2frun%2fslapd-RSINC-LOCAL.socket' '-x' '-D' 'cn=Directory Manager' '-y' '/tmp/tmpO1Mz2N'
2016-07-12T18:52:17Z DEBUG Process finished, return code=0
2016-07-12T18:52:17Z DEBUG stdout=add objectclass:
top
nsSlapdPlugin
extensibleObject
add cn:
ipa_pwd_extop
add nsslapd-pluginpath:
libipa_pwd_extop
add nsslapd-plugininitfunc:
ipapwd_init
add nsslapd-plugintype:
extendedop
add nsslapd-pluginbetxn:
on
add nsslapd-pluginenabled:
on
add nsslapd-pluginid:
ipa_pwd_extop
add nsslapd-pluginversion:
1.0
add nsslapd-pluginvendor:
RedHat
add nsslapd-plugindescription:
Support saving passwords in multiple formats for different consumers (krb5, samba, freeradius, etc.)
add nsslapd-plugin-depends-on-type:
database
add nsslapd-realmTree:
dc=rsinc,dc=local
adding new entry "cn=ipa_pwd_extop,cn=plugins,cn=config"
modify complete
2016-07-12T18:52:17Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-RSINC-LOCAL.socket/??base )
2016-07-12T18:52:17Z DEBUG duration: 0 seconds
2016-07-12T18:52:17Z DEBUG [6/8]: enable GSSAPI for replication
2016-07-12T18:52:18Z DEBUG flushing ldaps://ipa03-aws.rsinc.local:636 from SchemaCache
2016-07-12T18:52:18Z DEBUG retrieving schema for SchemaCache url=ldaps://ipa03-aws.rsinc.local:636 conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x7fa07e8>
2016-07-12T18:52:18Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:19Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:20Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:20Z DEBUG flushing ldaps://ipa01-aws.rsinc.local:636 from SchemaCache
2016-07-12T18:52:20Z DEBUG retrieving schema for SchemaCache url=ldaps://ipa01-aws.rsinc.local:636 conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x7fbf710>
2016-07-12T18:52:22Z INFO Setting agreement cn=meToipa03-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:24Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa03-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:26Z INFO Replication Update in progress: FALSE: status: 0 Replica acquired successfully: Incremental update succeeded: start: 0: end: 0
2016-07-12T18:52:26Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:26Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:26Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:28Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:29Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:29Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:29Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:29Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:30Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:31Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:31Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:31Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:31Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:32Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:33Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:33Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:33Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:33Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:34Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:35Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:35Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:35Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:35Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:36Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:37Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:37Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:38Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:38Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:39Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:40Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:40Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:40Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:40Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:41Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:42Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:42Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:42Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:42Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:43Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:44Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:44Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:45Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:45Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:46Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:47Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:47Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:47Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:47Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:48Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:49Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:49Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:49Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:49Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:50Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:51Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:51Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:51Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:51Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:52Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:53Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:53Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:53Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:53Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:54Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:55Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:55Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:55Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:55Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:56Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:57Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:57Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:57Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:57Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:52:58Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:52:59Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:52:59Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:52:59Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:52:59Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:00Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:01Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:01Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:02Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:02Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:03Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:04Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:04Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:05Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:05Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:06Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:07Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:07Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:07Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:07Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:08Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:09Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:09Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:09Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:09Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:10Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:11Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:11Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:11Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:11Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:12Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:13Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:13Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:13Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:13Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:14Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:15Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:15Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:15Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:15Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:16Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:17Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:17Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:17Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:17Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:18Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:19Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:19Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:19Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:19Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:20Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:21Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:21Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:22Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:22Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:23Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:24Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:24Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:24Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:24Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:25Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:26Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:26Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:26Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:26Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:27Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:28Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:28Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:29Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:29Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:30Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:31Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:31Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:31Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:31Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:32Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:33Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:33Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:33Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:33Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:34Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:35Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:35Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:36Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:36Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:37Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:38Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:38Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:38Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:38Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:39Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:40Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:40Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:41Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:41Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:42Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:43Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:43Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:43Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:43Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:44Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:45Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:45Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:45Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:45Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:46Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:47Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:47Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:47Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:47Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:48Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:49Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:49Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:49Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:49Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:50Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:51Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:51Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:52Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:52Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:53Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:54Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:54Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:54Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:54Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:55Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:56Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:56Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:57Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:57Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:53:58Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:53:59Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:53:59Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:53:59Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:53:59Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:00Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:01Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:01Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:01Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:01Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:02Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:03Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:03Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:03Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:03Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:04Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:05Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:05Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:05Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:05Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:06Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:07Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:07Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:08Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:08Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:09Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:10Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:10Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:10Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:10Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:11Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:12Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:12Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:12Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:12Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:13Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:14Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:14Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:15Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:15Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:16Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:17Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:17Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:17Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:17Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:18Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:19Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:19Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:19Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:19Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:20Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:21Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:21Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:21Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:21Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:22Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:23Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:23Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:23Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:23Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:24Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:25Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:25Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:26Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:26Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:27Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:28Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:28Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:28Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:28Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:29Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:30Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:30Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:30Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:30Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:31Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:32Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:32Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:32Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:32Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:33Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:34Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:34Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:35Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:35Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:36Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:37Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:37Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:37Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:37Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:38Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:39Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:39Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:39Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:39Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:40Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:41Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:41Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:41Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:41Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:42Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:43Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:43Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:43Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:43Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:44Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:45Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:45Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:46Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:46Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:47Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:48Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:48Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:49Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:49Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:50Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:51Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:51Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:51Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:51Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:52Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:53Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:53Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:54Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:54Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:55Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:56Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:56Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:56Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:56Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:57Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:54:58Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:54:58Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:54:58Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:54:58Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:54:59Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:00Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:00Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:00Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:00Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:01Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:02Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:02Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:02Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:02Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:03Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:04Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:04Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:04Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:04Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:05Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:06Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:06Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:07Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:07Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:08Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:09Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:09Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:09Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:09Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:10Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:11Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:11Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:11Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:11Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:12Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:13Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:13Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:13Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:13Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:14Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:15Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:15Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:15Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:15Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:16Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:17Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:17Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:17Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:17Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:18Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:19Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:19Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:19Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:19Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:20Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:21Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:21Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:21Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:21Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:23Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:24Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:24Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:24Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:24Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:25Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:26Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:26Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:26Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:26Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:27Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:28Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:28Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:28Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:28Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:29Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:30Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:30Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:30Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:30Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:31Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:32Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:32Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:32Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:32Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:33Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:34Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:34Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:35Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:35Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:36Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:37Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:37Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:37Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:37Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:38Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:39Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:39Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:39Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:39Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:40Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:41Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:41Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:41Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:41Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:42Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:44Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:44Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:44Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:44Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:45Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:46Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:46Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:46Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:46Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:47Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:48Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:48Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:49Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:49Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:50Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:51Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:51Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:51Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:51Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:52Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:53Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:53Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:53Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:53Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:54Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:55Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:55Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:55Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:55Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:56Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:57Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:57Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:57Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:57Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:55:58Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:55:59Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:55:59Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:55:59Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:55:59Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:56:00Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:56:01Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:56:01Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:56:01Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:56:01Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:56:02Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:56:03Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:56:03Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:56:04Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:56:04Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:56:05Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:56:06Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:56:06Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:56:06Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:56:06Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:56:07Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:56:08Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:56:08Z INFO Getting ldap service principals for conversion: (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) and (krbprincipalname=ldap/ipa01-aws.rsinc.local at RSINC.LOCAL)
2016-07-12T18:56:09Z DEBUG Unable to find entry for (krbprincipalname=ldap/ipa03-aws.rsinc.local at RSINC.LOCAL) on ipa01-aws.rsinc.local:636
2016-07-12T18:56:09Z INFO Setting agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch
2016-07-12T18:56:10Z INFO Deleting schedule 2358-2359 0 from agreement cn=meToipa01-aws.rsinc.local,cn=replica,cn=dc\=rsinc\,dc\=local,cn=mapping tree,cn=config
2016-07-12T18:56:11Z INFO Replication Update in progress: FALSE: status: 1 Can't acquire busy replica: start: 0: end: 0
2016-07-12T18:56:11Z DEBUG Traceback (most recent call last):
File "/usr/lib/python2.7/site-packages/ipaserver/install/service.py", line 418, in start_creation
run_step(full_msg, method)
File "/usr/lib/python2.7/site-packages/ipaserver/install/service.py", line 408, in run_step
method()
File "/usr/lib/python2.7/site-packages/ipaserver/install/krbinstance.py", line 438, in __convert_to_gssapi_replication
r_bindpw=self.dm_password)
File "/usr/lib/python2.7/site-packages/ipaserver/install/replication.py", line 1104, in convert_to_gssapi_replication
self.gssapi_update_agreements(self.conn, r_conn)
File "/usr/lib/python2.7/site-packages/ipaserver/install/replication.py", line 797, in gssapi_update_agreements
self.setup_krb_princs_as_replica_binddns(a, b)
File "/usr/lib/python2.7/site-packages/ipaserver/install/replication.py", line 767, in setup_krb_princs_as_replica_binddns
(a_dn, b_dn) = self.get_replica_principal_dns(a, b, retries=100)
File "/usr/lib/python2.7/site-packages/ipaserver/install/replication.py", line 751, in get_replica_principal_dns
raise RuntimeError(error)
RuntimeError: One of the ldap service principals is missing. Replication agreement cannot be converted.
Replication error message: Can't acquire busy replica
2016-07-12T18:56:11Z DEBUG [error] RuntimeError: One of the ldap service principals is missing. Replication agreement cannot be converted.
Replication error message: Can't acquire busy replica
2016-07-12T18:56:11Z DEBUG File "/usr/lib/python2.7/site-packages/ipapython/admintool.py", line 171, in execute
return_value = self.run()
File "/usr/lib/python2.7/site-packages/ipapython/install/cli.py", line 311, in run
cfgr.run()
File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 281, in run
self.execute()
File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 303, in execute
for nothing in self._executor():
File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 343, in __runner
self._handle_exception(exc_info)
File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 365, in _handle_exception
util.raise_exc_info(exc_info)
File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 333, in __runner
step()
File "/usr/lib/python2.7/site-packages/ipapython/install/util.py", line 87, in run_generator_with_yield_from
raise_exc_info(exc_info)
File "/usr/lib/python2.7/site-packages/ipapython/install/util.py", line 65, in run_generator_with_yield_from
value = gen.send(prev_value)
File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 539, in _configure
executor.next()
File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 343, in __runner
self._handle_exception(exc_info)
File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 421, in _handle_exception
self.__parent._handle_exception(exc_info)
File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 365, in _handle_exception
util.raise_exc_info(exc_info)
File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 418, in _handle_exception
super(ComponentBase, self)._handle_exception(exc_info)
File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 365, in _handle_exception
util.raise_exc_info(exc_info)
File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 333, in __runner
step()
File "/usr/lib/python2.7/site-packages/ipapython/install/util.py", line 87, in run_generator_with_yield_from
raise_exc_info(exc_info)
File "/usr/lib/python2.7/site-packages/ipapython/install/util.py", line 65, in run_generator_with_yield_from
value = gen.send(prev_value)
File "/usr/lib/python2.7/site-packages/ipapython/install/common.py", line 63, in _install
for nothing in self._installer(self.parent):
File "/usr/lib/python2.7/site-packages/ipaserver/install/server/replicainstall.py", line 901, in main
install(self)
File "/usr/lib/python2.7/site-packages/ipaserver/install/server/replicainstall.py", line 295, in decorated
func(installer)
File "/usr/lib/python2.7/site-packages/ipaserver/install/server/replicainstall.py", line 618, in install
krb = install_krb(config, setup_pkinit=not options.no_pkinit)
File "/usr/lib/python2.7/site-packages/ipaserver/install/server/replicainstall.py", line 93, in install_krb
setup_pkinit, pkcs12_info)
File "/usr/lib/python2.7/site-packages/ipaserver/install/krbinstance.py", line 214, in create_replica
self.start_creation(runtime=30)
File "/usr/lib/python2.7/site-packages/ipaserver/install/service.py", line 418, in start_creation
run_step(full_msg, method)
File "/usr/lib/python2.7/site-packages/ipaserver/install/service.py", line 408, in run_step
method()
File "/usr/lib/python2.7/site-packages/ipaserver/install/krbinstance.py", line 438, in __convert_to_gssapi_replication
r_bindpw=self.dm_password)
File "/usr/lib/python2.7/site-packages/ipaserver/install/replication.py", line 1104, in convert_to_gssapi_replication
self.gssapi_update_agreements(self.conn, r_conn)
File "/usr/lib/python2.7/site-packages/ipaserver/install/replication.py", line 797, in gssapi_update_agreements
self.setup_krb_princs_as_replica_binddns(a, b)
File "/usr/lib/python2.7/site-packages/ipaserver/install/replication.py", line 767, in setup_krb_princs_as_replica_binddns
(a_dn, b_dn) = self.get_replica_principal_dns(a, b, retries=100)
File "/usr/lib/python2.7/site-packages/ipaserver/install/replication.py", line 751, in get_replica_principal_dns
raise RuntimeError(error)
2016-07-12T18:56:11Z DEBUG The ipa-replica-install command failed, exception: RuntimeError: One of the ldap service principals is missing. Replication agreement cannot be converted.
Replication error message: Can't acquire busy replica
2016-07-12T18:56:11Z ERROR One of the ldap service principals is missing. Replication agreement cannot be converted.
Replication error message: Can't acquire busy replica
More information about the Freeipa-users
mailing list