2019-09-25T08:09:42Z DEBUG Logging to /var/log/ipaclient-install.log 2019-09-25T08:09:42Z DEBUG ipa-client-install was invoked with arguments [] and options: {'no_dns_sshfp': False, 'force': False, 'verbose': False, 'ip_addresses': [CheckedIPAddress('192.168.4.137')], 'configure_firefox': False, 'realm_name': 'LIN.MY.DOMAIN', 'force_ntpd': False, 'on_master': False, 'no_nisdomain': False, 'ssh_trust_dns': False, 'principal': 'admin', 'keytab': None, 'no_ntp': False, 'domain_name': 'lin.my.domain', 'request_cert': False, 'fixed_primary': False, 'no_ac': False, 'no_sudo': False, 'ca_cert_files': None, 'all_ip_addresses': False, 'kinit_attempts': None, 'ntp_pool': None, 'ntp_servers': None, 'enable_dns_updates': False, 'no_sshd': False, 'no_sssd': False, 'no_krb5_offline_passwords': False, 'servers': None, 'no_ssh': False, 'force_join': True, 'firefox_dir': None, 'unattended': True, 'quiet': False, 'nisdomain': None, 'prompt_password': False, 'host_name': 'ipaclientlan.lin.my.domain', 'permit': False, 'automount_location': None, 'preserve_sssd': False, 'mkhomedir': True, 'log_file': None, 'uninstall': False} 2019-09-25T08:09:42Z DEBUG IPA version 4.6.90.pre1+git20180411 2019-09-25T08:09:42Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2019-09-25T08:09:42Z DEBUG [IPA Discovery] 2019-09-25T08:09:42Z DEBUG Starting IPA discovery with domain=lin.my.domain, servers=None, hostname=ipaclientlan.lin.my.domain 2019-09-25T08:09:42Z DEBUG Search for LDAP SRV record in lin.my.domain 2019-09-25T08:09:42Z DEBUG Search DNS for SRV record of _ldap._tcp.lin.my.domain 2019-09-25T08:09:42Z DEBUG DNS record found: 0 100 389 ipa1.lin.my.domain. 2019-09-25T08:09:42Z DEBUG DNS record found: 0 100 389 ipa2.lin.my.domain. 2019-09-25T08:09:42Z DEBUG [Kerberos realm search] 2019-09-25T08:09:42Z DEBUG Kerberos realm forced 2019-09-25T08:09:42Z DEBUG Search DNS for SRV record of _kerberos._udp.lin.my.domain 2019-09-25T08:09:42Z DEBUG DNS record found: 0 100 88 ipa1.lin.my.domain. 2019-09-25T08:09:42Z DEBUG DNS record found: 0 100 88 ipa2.lin.my.domain. 2019-09-25T08:09:42Z DEBUG [LDAP server check] 2019-09-25T08:09:42Z DEBUG Verifying that ipa1.lin.my.domain (realm LIN.MY.DOMAIN) is an IPA server 2019-09-25T08:09:42Z DEBUG Init LDAP connection to: ldap://ipa1.lin.my.domain:389 2019-09-25T08:09:42Z DEBUG Search LDAP server for IPA base DN 2019-09-25T08:09:42Z DEBUG Check if naming context 'dc=lin,dc=my,dc=domain' is for IPA 2019-09-25T08:09:42Z DEBUG Naming context 'dc=lin,dc=my,dc=domain' is a valid IPA context 2019-09-25T08:09:42Z DEBUG Search for (objectClass=krbRealmContainer) in dc=lin,dc=my,dc=domain (sub) 2019-09-25T08:09:42Z DEBUG Found: cn=LIN.MY.DOMAIN,cn=kerberos,dc=lin,dc=my,dc=domain 2019-09-25T08:09:42Z DEBUG Discovery result: Success; server=ipa1.lin.my.domain, domain=lin.my.domain, kdc=ipa1.lin.my.domain,ipa2.lin.my.domain, basedn=dc=lin,dc=my,dc=domain 2019-09-25T08:09:42Z DEBUG Validated servers: ipa1.lin.my.domain 2019-09-25T08:09:42Z DEBUG will use discovered domain: lin.my.domain 2019-09-25T08:09:42Z DEBUG Start searching for LDAP SRV record in "lin.my.domain" (Validating DNS Discovery) and its sub-domains 2019-09-25T08:09:42Z DEBUG Search DNS for SRV record of _ldap._tcp.lin.my.domain 2019-09-25T08:09:42Z DEBUG DNS record found: 0 100 389 ipa2.lin.my.domain. 2019-09-25T08:09:42Z DEBUG DNS record found: 0 100 389 ipa1.lin.my.domain. 2019-09-25T08:09:42Z DEBUG DNS validated, enabling discovery 2019-09-25T08:09:42Z DEBUG will use discovered server: ipa1.lin.my.domain 2019-09-25T08:09:42Z INFO Discovery was successful! 2019-09-25T08:09:42Z DEBUG will use discovered realm: LIN.MY.DOMAIN 2019-09-25T08:09:42Z DEBUG will use discovered basedn: dc=lin,dc=my,dc=domain 2019-09-25T08:09:42Z INFO Client hostname: ipaclientlan.lin.my.domain 2019-09-25T08:09:42Z DEBUG Hostname source: Provided as option 2019-09-25T08:09:42Z INFO Realm: LIN.MY.DOMAIN 2019-09-25T08:09:42Z DEBUG Realm source: Discovered from LDAP DNS records in ipa1.lin.my.domain 2019-09-25T08:09:42Z INFO DNS Domain: lin.my.domain 2019-09-25T08:09:42Z DEBUG DNS Domain source: Discovered LDAP SRV records from lin.my.domain 2019-09-25T08:09:42Z INFO IPA Server: ipa1.lin.my.domain 2019-09-25T08:09:42Z DEBUG IPA Server source: Discovered from LDAP DNS records in ipa1.lin.my.domain 2019-09-25T08:09:42Z INFO BaseDN: dc=lin,dc=my,dc=domain 2019-09-25T08:09:42Z DEBUG BaseDN source: From IPA server ldap://ipa1.lin.my.domain:389 2019-09-25T08:09:42Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2019-09-25T08:09:42Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2019-09-25T08:09:42Z DEBUG Starting external process 2019-09-25T08:09:42Z DEBUG args=['/usr/sbin/ipa-rmkeytab', '-k', '/etc/krb5.keytab', '-r', 'LIN.MY.DOMAIN'] 2019-09-25T08:09:42Z DEBUG Process finished, return code=5 2019-09-25T08:09:42Z DEBUG stdout= 2019-09-25T08:09:42Z DEBUG stderr=domaine introuvable 2019-09-25T08:09:42Z DEBUG Backing up system configuration file '/etc/hostname' 2019-09-25T08:09:42Z DEBUG Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index' 2019-09-25T08:09:42Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2019-09-25T08:09:42Z DEBUG Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state' 2019-09-25T08:09:42Z DEBUG Starting external process 2019-09-25T08:09:42Z DEBUG args=['/usr/bin/hostnamectl', 'set-hostname', 'ipaclientlan.lin.my.domain'] 2019-09-25T08:09:42Z DEBUG Process finished, return code=0 2019-09-25T08:09:42Z DEBUG stdout= 2019-09-25T08:09:42Z DEBUG stderr= 2019-09-25T08:09:42Z DEBUG Starting external process 2019-09-25T08:09:42Z DEBUG args=['/usr/sbin/service', 'ntp', 'status', ''] 2019-09-25T08:09:42Z DEBUG Process finished, return code=3 2019-09-25T08:09:42Z DEBUG stdout=● ntp.service Loaded: masked (/dev/null; bad) Active: inactive (dead) 2019-09-25T08:09:42Z DEBUG stderr= 2019-09-25T08:09:42Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2019-09-25T08:09:42Z DEBUG Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state' 2019-09-25T08:09:42Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2019-09-25T08:09:42Z DEBUG Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state' 2019-09-25T08:09:42Z INFO Synchronizing time 2019-09-25T08:09:42Z DEBUG Search DNS for SRV record of _ntp._udp.lin.my.domain 2019-09-25T08:09:42Z DEBUG DNS record found: 0 100 123 ipa2.lin.my.domain. 2019-09-25T08:09:42Z DEBUG DNS record found: 0 100 123 ipa1.lin.my.domain. 2019-09-25T08:09:42Z DEBUG Starting external process 2019-09-25T08:09:42Z DEBUG args=['/bin/systemctl', 'is-enabled', 'chronyd.service'] 2019-09-25T08:09:42Z DEBUG Process finished, return code=0 2019-09-25T08:09:42Z DEBUG stdout=enabled 2019-09-25T08:09:42Z DEBUG stderr= 2019-09-25T08:09:42Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2019-09-25T08:09:42Z DEBUG Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state' 2019-09-25T08:09:42Z DEBUG Configuring chrony 2019-09-25T08:09:42Z DEBUG Setting time servers: 2019-09-25T08:09:42Z DEBUG 'ipa2.lin.my.domain' 2019-09-25T08:09:42Z DEBUG 'ipa1.lin.my.domain' 2019-09-25T08:09:42Z DEBUG Backing up '/etc/chrony/chrony.conf' 2019-09-25T08:09:42Z DEBUG Backing up system configuration file '/etc/chrony/chrony.conf' 2019-09-25T08:09:42Z DEBUG Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index' 2019-09-25T08:09:42Z DEBUG Writing configuration to '/etc/chrony/chrony.conf' 2019-09-25T08:09:42Z INFO Configuration of chrony was changed by installer. 2019-09-25T08:09:42Z DEBUG Starting external process 2019-09-25T08:09:42Z DEBUG args=['/bin/systemctl', 'enable', 'chronyd.service'] 2019-09-25T08:09:42Z DEBUG Process finished, return code=1 2019-09-25T08:09:42Z DEBUG stdout= 2019-09-25T08:09:42Z DEBUG stderr=Failed to enable unit: Refusing to operate on linked unit file chronyd.service 2019-09-25T08:09:42Z DEBUG Starting external process 2019-09-25T08:09:42Z DEBUG args=['/bin/systemctl', 'restart', 'chronyd.service'] 2019-09-25T08:09:42Z DEBUG Process finished, return code=0 2019-09-25T08:09:42Z DEBUG stdout= 2019-09-25T08:09:42Z DEBUG stderr= 2019-09-25T08:09:42Z DEBUG Starting external process 2019-09-25T08:09:42Z DEBUG args=['/bin/systemctl', 'is-active', 'chronyd.service'] 2019-09-25T08:09:42Z DEBUG Process finished, return code=0 2019-09-25T08:09:42Z DEBUG stdout=active 2019-09-25T08:09:42Z DEBUG stderr= 2019-09-25T08:09:42Z INFO Attempting to sync time with chronyc. 2019-09-25T08:09:42Z DEBUG Starting external process 2019-09-25T08:09:42Z DEBUG args=['/usr/bin/chronyc', 'waitsync', '3', '-d'] 2019-09-25T08:09:52Z DEBUG Process finished, return code=0 2019-09-25T08:09:52Z DEBUG stdout=try: 1, refid: 00000000, correction: 0.000000000, skew: 0.000 try: 2, refid: 0A008AA5, correction: 0.000008726, skew: 1.433 2019-09-25T08:09:52Z DEBUG stderr= 2019-09-25T08:09:52Z INFO Time synchronization was successful. 2019-09-25T08:09:52Z DEBUG Starting external process 2019-09-25T08:09:52Z DEBUG args=['/bin/keyctl', 'get_persistent', '@s', '0'] 2019-09-25T08:09:52Z DEBUG Process finished, return code=0 2019-09-25T08:09:52Z DEBUG stdout=236813402 2019-09-25T08:09:52Z DEBUG stderr= 2019-09-25T08:09:52Z DEBUG Enabling persistent keyring CCACHE 2019-09-25T08:09:52Z DEBUG Writing Kerberos configuration to /tmp/tmpXe29wj: 2019-09-25T08:09:52Z DEBUG #File modified by ipa-client-install includedir /etc/krb5.conf.d/ includedir /var/lib/sss/pubconf/krb5.include.d/ [libdefaults] default_realm = LIN.MY.DOMAIN dns_lookup_realm = false dns_lookup_kdc = false rdns = false dns_canonicalize_hostname = false ticket_lifetime = 24h forwardable = true udp_preference_limit = 0 default_ccache_name = KEYRING:persistent:%{uid} [realms] LIN.MY.DOMAIN = { kdc = ipa1.lin.my.domain:88 master_kdc = ipa1.lin.my.domain:88 admin_server = ipa1.lin.my.domain:749 kpasswd_server = ipa1.lin.my.domain:464 default_domain = lin.my.domain pkinit_anchors = FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pem pkinit_pool = FILE:/var/lib/ipa-client/pki/ca-bundle.pem } [domain_realm] .lin.my.domain = LIN.MY.DOMAIN lin.my.domain = LIN.MY.DOMAIN ipaclientlan.lin.my.domain = LIN.MY.DOMAIN 2019-09-25T08:09:52Z DEBUG Writing configuration file /tmp/tmpXe29wj 2019-09-25T08:09:52Z DEBUG #File modified by ipa-client-install includedir /etc/krb5.conf.d/ includedir /var/lib/sss/pubconf/krb5.include.d/ [libdefaults] default_realm = LIN.MY.DOMAIN dns_lookup_realm = false dns_lookup_kdc = false rdns = false dns_canonicalize_hostname = false ticket_lifetime = 24h forwardable = true udp_preference_limit = 0 default_ccache_name = KEYRING:persistent:%{uid} [realms] LIN.MY.DOMAIN = { kdc = ipa1.lin.my.domain:88 master_kdc = ipa1.lin.my.domain:88 admin_server = ipa1.lin.my.domain:749 kpasswd_server = ipa1.lin.my.domain:464 default_domain = lin.my.domain pkinit_anchors = FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pem pkinit_pool = FILE:/var/lib/ipa-client/pki/ca-bundle.pem } [domain_realm] .lin.my.domain = LIN.MY.DOMAIN lin.my.domain = LIN.MY.DOMAIN ipaclientlan.lin.my.domain = LIN.MY.DOMAIN 2019-09-25T08:09:52Z DEBUG Initializing principal admin@LIN.MY.DOMAIN using password 2019-09-25T08:09:52Z DEBUG Starting external process 2019-09-25T08:09:52Z DEBUG args=['/usr/bin/kinit', 'admin@LIN.MY.DOMAIN', '-c', '/tmp/krbcc5_TWr5/ccache'] 2019-09-25T08:09:52Z DEBUG Process finished, return code=0 2019-09-25T08:09:52Z DEBUG stdout=Password for admin@LIN.MY.DOMAIN: 2019-09-25T08:09:52Z DEBUG stderr= 2019-09-25T08:09:52Z DEBUG trying to retrieve CA cert via LDAP from ipa1.lin.my.domain 2019-09-25T08:09:52Z DEBUG retrieving schema for SchemaCache url=ldap://ipa1.lin.my.domain:389 conn= 2019-09-25T08:09:52Z INFO Successfully retrieved CA cert Subject: CN=Certificate Authority,O=LIN.MY.DOMAIN Issuer: CN=Certificate Authority,O=LIN.MY.DOMAIN Valid From: 2019-09-19 07:38:22 Valid Until: 2039-09-19 07:38:22 2019-09-25T08:09:52Z DEBUG Starting external process 2019-09-25T08:09:52Z DEBUG args=['/usr/sbin/ipa-join', '-s', 'ipa1.lin.my.domain', '-b', 'dc=lin,dc=my,dc=domain', '-h', 'ipaclientlan.lin.my.domain', '-f'] 2019-09-25T08:09:53Z DEBUG Process finished, return code=0 2019-09-25T08:09:53Z DEBUG stdout= 2019-09-25T08:09:53Z DEBUG stderr=Keytab successfully retrieved and stored in: /etc/krb5.keytab Certificate subject base is: O=LIN.MY.DOMAIN 2019-09-25T08:09:53Z INFO Enrolled in IPA realm LIN.MY.DOMAIN 2019-09-25T08:09:53Z DEBUG Starting external process 2019-09-25T08:09:53Z DEBUG args=['/usr/bin/kdestroy'] 2019-09-25T08:09:53Z DEBUG Process finished, return code=0 2019-09-25T08:09:53Z DEBUG stdout= 2019-09-25T08:09:53Z DEBUG stderr= 2019-09-25T08:09:53Z DEBUG Initializing principal host/ipaclientlan.lin.my.domain@LIN.MY.DOMAIN using keytab /etc/krb5.keytab 2019-09-25T08:09:53Z DEBUG using ccache /etc/ipa/.dns_ccache 2019-09-25T08:09:53Z DEBUG Attempt 1/5: success 2019-09-25T08:09:53Z DEBUG Backing up system configuration file '/etc/ipa/default.conf' 2019-09-25T08:09:53Z DEBUG -> Not backing up - '/etc/ipa/default.conf' doesn't exist 2019-09-25T08:09:53Z DEBUG Writing configuration file /etc/ipa/default.conf 2019-09-25T08:09:53Z DEBUG #File modified by ipa-client-install [global] basedn = dc=lin,dc=my,dc=domain realm = LIN.MY.DOMAIN domain = lin.my.domain server = ipa1.lin.my.domain host = ipaclientlan.lin.my.domain xmlrpc_uri = https://ipa1.lin.my.domain/ipa/xml enable_ra = True 2019-09-25T08:09:53Z INFO Created /etc/ipa/default.conf 2019-09-25T08:09:53Z DEBUG Backing up system configuration file '/etc/sssd/sssd.conf' 2019-09-25T08:09:53Z DEBUG Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index' 2019-09-25T08:09:53Z DEBUG Backing up system configuration file '/etc/nsswitch.conf' 2019-09-25T08:09:53Z DEBUG Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index' 2019-09-25T08:09:53Z DEBUG Updating configuration file /etc/nsswitch.conf 2019-09-25T08:09:53Z DEBUG # /etc/nsswitch.conf # # Example configuration of GNU Name Service Switch functionality. # If you have the `glibc-doc-reference' and `info' packages installed, try: # `info libc "Name Service Switch"' for information about this file. # pre_auth-client-config # passwd: compat systemd sss passwd: compat sss # pre_auth-client-config # group: compat systemd sss group: compat sss # pre_auth-client-config # shadow: compat sss shadow: compat gshadow: files hosts: files mdns4_minimal [NOTFOUND=return] dns myhostname networks: files protocols: db files services: db files sss ethers: db files rpc: db files # pre_auth-client-config # netgroup: nis sss netgroup: nis sudoers: files sss 2019-09-25T08:09:53Z INFO Configured sudoers in /etc/nsswitch.conf 2019-09-25T08:09:53Z DEBUG File "/usr/lib/python2.7/dist-packages/ipapython/admintool.py", line 174, in execute return_value = self.run() File "/usr/lib/python2.7/dist-packages/ipapython/install/cli.py", line 319, in run return cfgr.run() File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 364, in run return self.execute() File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 389, in execute for rval in self._executor(): File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 434, in __runner exc_handler(exc_info) File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 463, in _handle_execute_exception self._handle_exception(exc_info) File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 453, in _handle_exception six.reraise(*exc_info) File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 424, in __runner step() File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 421, in step = lambda: next(self.__gen) File "/usr/lib/python2.7/dist-packages/ipapython/install/util.py", line 81, in run_generator_with_yield_from six.reraise(*exc_info) File "/usr/lib/python2.7/dist-packages/ipapython/install/util.py", line 59, in run_generator_with_yield_from value = gen.send(prev_value) File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 658, in _configure next(executor) File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 434, in __runner exc_handler(exc_info) File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 463, in _handle_execute_exception self._handle_exception(exc_info) File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 521, in _handle_exception self.__parent._handle_exception(exc_info) File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 453, in _handle_exception six.reraise(*exc_info) File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 518, in _handle_exception super(ComponentBase, self)._handle_exception(exc_info) File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 453, in _handle_exception six.reraise(*exc_info) File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 424, in __runner step() File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 421, in step = lambda: next(self.__gen) File "/usr/lib/python2.7/dist-packages/ipapython/install/util.py", line 81, in run_generator_with_yield_from six.reraise(*exc_info) File "/usr/lib/python2.7/dist-packages/ipapython/install/util.py", line 59, in run_generator_with_yield_from value = gen.send(prev_value) File "/usr/lib/python2.7/dist-packages/ipapython/install/common.py", line 65, in _install for unused in self._installer(self.parent): File "/usr/lib/python2.7/dist-packages/ipaclient/install/client.py", line 3638, in main install(self) File "/usr/lib/python2.7/dist-packages/ipaclient/install/client.py", line 2405, in install _install(options) File "/usr/lib/python2.7/dist-packages/ipaclient/install/client.py", line 2672, in _install options, client_domain, hostname): File "/usr/lib/python2.7/dist-packages/ipaclient/install/client.py", line 961, in configure_sssd_conf sssdconfig.write(paths.SSSD_CONF) File "/usr/lib/python2.7/dist-packages/SSSDConfig/__init__.py", line 1523, in write output = self.dump(self.opts).encode('utf-8') 2019-09-25T08:09:53Z DEBUG The ipa-client-install command failed, exception: UnicodeDecodeError: 'ascii' codec can't decode byte 0xe2 in position 1316: ordinal not in range(128) 2019-09-25T08:09:53Z ERROR 'ascii' codec can't decode byte 0xe2 in position 1316: ordinal not in range(128) 2019-09-25T08:09:53Z ERROR The ipa-client-install command failed. See /var/log/ipaclient-install.log for more information